Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x568-473g-qj6x

Опубликовано: 28 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed by users with administrative privileges. An attacker could thereby obtain higher permissions. The attacker must already have access to the corresponding local system to be able to exchange the files.

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed by users with administrative privileges. An attacker could thereby obtain higher permissions. The attacker must already have access to the corresponding local system to be able to exchange the files.

EPSS

Процентиль: 32%
0.00123
Низкий

7.3 High

CVSS3

Дефекты

CWE-269
CWE-732

Связанные уязвимости

CVSS3: 7.3
nvd
почти 4 года назад

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

EPSS

Процентиль: 32%
0.00123
Низкий

7.3 High

CVSS3

Дефекты

CWE-269
CWE-732