Логотип exploitDog
bind:CVE-2025-43001
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43001

Количество 3

Количество 3

nvd логотип

CVE-2025-43001

7 месяцев назад

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-25qh-97qq-x7c4

7 месяцев назад

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.

CVSS3: 6.9
EPSS: Низкий
fstec логотип

BDU:2025-16216

7 месяцев назад

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с некорректным присваиванием привилегий, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43001

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.

CVSS3: 6.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-25qh-97qq-x7c4

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.

CVSS3: 6.9
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-16216

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с некорректным присваиванием привилегий, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.9
0%
Низкий
7 месяцев назад

Уязвимостей на страницу