Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp9f-q9f5-cghf

Опубликовано: 03 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

EPSS

Процентиль: 39%
0.00173
Низкий

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

EPSS

Процентиль: 39%
0.00173
Низкий

7.5 High

CVSS3

Дефекты

CWE-89