Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w973-74m8-8xw5

Опубликовано: 12 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

EPSS

Процентиль: 19%
0.00059
Низкий

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.4
nvd
около 4 лет назад

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

EPSS

Процентиль: 19%
0.00059
Низкий

Дефекты

CWE-427