Описание
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
Ссылки
- Not Applicable
- Release NotesVendor Advisory
- Not Applicable
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.398 (исключая)
cpe:2.3:a:heimdalsecurity:heimdal_premium_security:*:*:*:*:*:*:*:*
EPSS
Процентиль: 6%
0.00023
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-281
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
EPSS
Процентиль: 6%
0.00023
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-281