Описание
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:gimmal:sherpa_connector_service:2020.2.20328.2050:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00216
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-428
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
EPSS
Процентиль: 44%
0.00216
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-428