Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23892

Опубликовано: 12 мая 2021
Источник: nvd
CVSS3: 8.2
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:mcafee:endpoint_security_for_linux_threat_prevention:*:*:*:*:*:linux:*:*
Версия от 10.5.0 (включая) до 10.7.5 (исключая)

EPSS

Процентиль: 5%
0.00022
Низкий

8.2 High

CVSS3

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59
CWE-367

Связанные уязвимости

CVSS3: 7
github
больше 3 лет назад

By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.

EPSS

Процентиль: 5%
0.00022
Низкий

8.2 High

CVSS3

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59
CWE-367