Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-26918

Опубликовано: 14 апр. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:filereplicationpro:file_replication_pro:7.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02407
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276
CWE-276

Связанные уязвимости

CVSS3: 9.8
github
почти 3 года назад

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

EPSS

Процентиль: 85%
0.02407
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276
CWE-276