Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wmf-4rwp-j5x8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

EPSS

Процентиль: 17%
0.00053
Низкий

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

EPSS

Процентиль: 17%
0.00053
Низкий

Дефекты

CWE-426