Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2rr-gcf8-2w6g

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with and (2) child processes that call the CreateProcess function and are executed with or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with and (2) child processes that call the CreateProcess function and are executed with or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

EPSS

Процентиль: 24%
0.00079
Низкий

Связанные уязвимости

nvd
почти 24 года назад

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

EPSS

Процентиль: 24%
0.00079
Низкий