Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qx2-7jwx-q6pj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

EPSS

Процентиль: 97%
0.40909
Средний

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость компонента SmartCard Authentication программного средства удаленного доступа SolarWinds DameWare Mini Remote Control, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.40909
Средний

Дефекты

CWE-20