Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99jf-rpjr-fwjv

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

EPSS

Процентиль: 6%
0.00165
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

EPSS

Процентиль: 6%
0.00165
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-428