Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24618

Опубликовано: 10 мар. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:heimdalsecurity:heimdal_premium_security:*:*:*:*:*:*:*:*
Версия до 2.5.398 (исключая)

EPSS

Процентиль: 6%
0.00023
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 7.8
github
почти 4 года назад

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.

EPSS

Процентиль: 6%
0.00023
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-281