Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8p62-8jvq-2hh6

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

EPSS

Процентиль: 19%
0.00062
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.7
nvd
больше 7 лет назад

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

EPSS

Процентиль: 19%
0.00062
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-284