Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h66f-8xvf-h765

Опубликовано: 13 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.

A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.

EPSS

Процентиль: 15%
0.00047
Низкий

7.8 High

CVSS3

Дефекты

CWE-648

Связанные уязвимости

CVSS3: 7.8
nvd
почти 2 года назад

A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.

CVSS3: 7.8
fstec
почти 2 года назад

Уязвимость агента установщика Windows программного обеспечения для автоматизированного программирования и создания документации для сборки печатных плат Unicam FX, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 15%
0.00047
Низкий

7.8 High

CVSS3

Дефекты

CWE-648