Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33r8-p23p-5pwc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

EPSS

Процентиль: 60%
0.00402
Низкий

7.3 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.3
nvd
почти 7 лет назад

The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

EPSS

Процентиль: 60%
0.00402
Низкий

7.3 High

CVSS3

Дефекты

CWE-732