Описание
The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation.
Ссылки
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0 (исключая)
cpe:2.3:a:comparex:miss_marple:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 90%
0.05409
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-494
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation.
EPSS
Процентиль: 90%
0.05409
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-494