Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5gm-xw9r-m7h2

Опубликовано: 31 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.

The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

7.8 High

CVSS3

Дефекты

CWE-379

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

7.8 High

CVSS3

Дефекты

CWE-379