Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj6f-97f2-wp7j

Опубликовано: 20 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.

An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.

EPSS

Процентиль: 24%
0.0008
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 лет назад

An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.

EPSS

Процентиль: 24%
0.0008
Низкий

7.8 High

CVSS3