Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccf8-r983-v699

Опубликовано: 06 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

EPSS

Процентиль: 25%
0.00084
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 6.6
nvd
больше 2 лет назад

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

EPSS

Процентиль: 25%
0.00084
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-281