Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-285c-cc6q-hwff

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.

EPSS

Процентиль: 2%
0.00112
Низкий

8.5 High

CVSS4

Дефекты

CWE-73

Связанные уязвимости

nvd
2 месяца назад

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.

EPSS

Процентиль: 2%
0.00112
Низкий

8.5 High

CVSS4

Дефекты

CWE-73