Логотип exploitDog
bind:CVE-2023-22947
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22947

Количество 3

Количество 3

nvd логотип

CVE-2023-22947

около 3 лет назад

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2023-22947

около 3 лет назад

Insecure folder permissions in the Windows installation path of Shibbo ...

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-fc86-55vx-x268

около 3 лет назад

** DISPUTED ** Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-22947

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

CVSS3: 7.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-22947

Insecure folder permissions in the Windows installation path of Shibbo ...

CVSS3: 7.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-fc86-55vx-x268

** DISPUTED ** Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

CVSS3: 7.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу