Описание
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
Ссылки
- ProductVendor Advisory
- ProductVendor Advisory
- Release NotesVendor Advisory
- ProductVendor Advisory
- ProductVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.14.14 (исключая)
Одновременно
cpe:2.3:a:aviatrix:vpn_client:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00048
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-428
Связанные уязвимости
github
больше 3 лет назад
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
EPSS
Процентиль: 15%
0.00048
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-428