Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-35471

Опубликовано: 13 мая 2025
Источник: nvd
CVSS3: 7.3
CVSS3: 7.8
EPSS Низкий

Описание

conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:conda-forge:miniforge:*:*:*:*:*:*:*:*
Версия до 24.5.0 (исключая)
cpe:2.3:a:conda-forge:openssl-feedstock:*:*:*:*:*:*:*:*
Версия до 2024-05-20 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00014
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.3
github
9 месяцев назад

conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.

EPSS

Процентиль: 2%
0.00014
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427