Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-638m-xxfq-rm3j

Опубликовано: 01 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.

EPSS

Процентиль: 92%
0.08126
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.

EPSS

Процентиль: 92%
0.08126
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502