Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr6v-r7qx-4973

Опубликовано: 04 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

EPSS

Процентиль: 20%
0.00066
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.8
nvd
10 месяцев назад

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

EPSS

Процентиль: 20%
0.00066
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-284