Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvf4-x9j7-vf2f

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16916.

An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16916.

EPSS

Процентиль: 76%
0.00993
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The update addresses the vulnerability by correcting how the Windows COM Server creates COM objects.</p>

CVSS3: 7.8
msrc
больше 4 лет назад

Windows COM Server Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость компонента Windows COM Server операционной системы Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 76%
0.00993
Низкий

7.8 High

CVSS3

Дефекты

CWE-269