Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vg2-hc44-37f3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'.

EPSS

Процентиль: 71%
0.00719
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

<p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation.</p>

CVSS3: 7.8
msrc
больше 4 лет назад

Windows Installer Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость установщика операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 71%
0.00719
Низкий

7.8 High

CVSS3

Дефекты

CWE-269