Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cqc-hhcp-cf94

Опубликовано: 26 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

CMService.exe creates the C:\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

CMService.exe creates the C:\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

EPSS

Процентиль: 3%
0.00016
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-269

Связанные уязвимости

nvd
2 месяца назад

CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

EPSS

Процентиль: 3%
0.00016
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-269