Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2826-h3cg-5m6j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-20