Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx9h-h562-86qx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An attacker who has already compromised the local system could use TinyWall Controller to gain additional privileges by attaching a debugger to the running process and modifying the code in memory. Vulnerability fixed in version 2.1.13.

An attacker who has already compromised the local system could use TinyWall Controller to gain additional privileges by attaching a debugger to the running process and modifying the code in memory. Vulnerability fixed in version 2.1.13.

EPSS

Процентиль: 74%
0.00837
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-502

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.

EPSS

Процентиль: 74%
0.00837
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-502