Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pp9v-vrjh-4q7m

Опубликовано: 02 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

EPSS

Процентиль: 34%
0.0014
Низкий

8.2 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 5.9
nvd
около 3 лет назад

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

EPSS

Процентиль: 34%
0.0014
Низкий

8.2 High

CVSS3

Дефекты

CWE-427