Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6634-g827-cg9w

Опубликовано: 05 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

EPSS

Процентиль: 10%
0.00036
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

EPSS

Процентиль: 10%
0.00036
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362