Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwx2-6cm4-jr73

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

EPSS

Процентиль: 29%
0.00105
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

EPSS

Процентиль: 29%
0.00105
Низкий

Дефекты

CWE-276