Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4996

Опубликовано: 06 нояб. 2023
Источник: nvd
CVSS3: 6.6
CVSS3: 8.8
EPSS Низкий

Описание

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:netskope:netskope:*:*:*:*:*:*:*:*
Версия до 101 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00084
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-281
CWE-281

Связанные уязвимости

CVSS3: 6.6
github
больше 2 лет назад

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

EPSS

Процентиль: 25%
0.00084
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-281
CWE-281