Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74vv-q3rm-9hv6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution.

An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This CVE is similar, but not identical to CVE-2020-24556.

A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution.

An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This CVE is similar, but not identical to CVE-2020-24556.

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This CVE is similar, but not identical to CVE-2020-24556.

CVSS3: 7.8
fstec
больше 5 лет назад

Уязвимость средства антивирусной защиты Trend Micro OfficeScan, связанная с ошибками управления привилегиями, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-269