Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrh7-rq69-242h

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

EPSS

Процентиль: 37%
0.00154
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 лет назад

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

EPSS

Процентиль: 37%
0.00154
Низкий

7.8 High

CVSS3

Дефекты

CWE-269