Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wjq-q3c8-8q2h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.

EPSS

Процентиль: 31%
0.00119
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.

EPSS

Процентиль: 31%
0.00119
Низкий

Дефекты

CWE-269