Логотип exploitDog
bind:CVE-2018-10172
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-10172

Количество 3

Количество 3

nvd логотип

CVE-2018-10172

почти 8 лет назад

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process. Note: This has been disputed by 3rd parties who argue this is a valid feature of Windows.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rpcp-46mr-7cgp

больше 3 лет назад

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2018-00773

почти 8 лет назад

Уязвимость функции LsaAddAccountRights файлового архиватора 7-Zip, позволяющая нарушителю обойти существующие ограничения доступа

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-10172

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process. Note: This has been disputed by 3rd parties who argue this is a valid feature of Windows.

CVSS3: 8.8
0%
Низкий
почти 8 лет назад
github логотип
GHSA-rpcp-46mr-7cgp

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2018-00773

Уязвимость функции LsaAddAccountRights файлового архиватора 7-Zip, позволяющая нарушителю обойти существующие ограничения доступа

CVSS3: 8.8
0%
Низкий
почти 8 лет назад

Уязвимостей на страницу