Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgfp-cfcp-654m

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.7

Описание

A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges.

A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

6.7 Medium

CVSS4

Дефекты

CWE-94

Связанные уязвимости

nvd
7 месяцев назад

A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

6.7 Medium

CVSS4

Дефекты

CWE-94