Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pc6-9cmx-jhrg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.

EPSS

Процентиль: 19%
0.0006
Низкий

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 5.5
nvd
около 5 лет назад

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.

EPSS

Процентиль: 19%
0.0006
Низкий

Дефекты

CWE-427