Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1484

Опубликовано: 22 апр. 2015
Источник: nvd
CVSS2: 6.9
EPSS Низкий

Описание

Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

Комментарий

CWE-426: Untrusted Search Path

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:symantec:workspace_streaming:6.1:sp8:*:*:*:*:*:*
cpe:2.3:a:symantec:workspace_streaming:7.5:sp1:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00068
Низкий

6.9 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

EPSS

Процентиль: 21%
0.00068
Низкий

6.9 Medium

CVSS2

Дефекты

NVD-CWE-Other