Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pfr-2xmv-j9v4

Опубликовано: 20 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

EPSS

Процентиль: 23%
0.00076
Низкий

7.3 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.3
nvd
больше 3 лет назад

A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 7.3
fstec
почти 4 года назад

Уязвимость службы Local Web Classification Server Service (LWCS) антивирусного программного средства Apex One, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код

EPSS

Процентиль: 23%
0.00076
Низкий

7.3 High

CVSS3

Дефекты

CWE-59