PT-2023-1379 · F5 · Big-Ip Edge Client

Publicado

2023-02-01

·

Atualizado

2023-10-04

·

CVE-2023-22283

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BIG-IP Edge Client for Windows versions 7.1.5 through 7.2.3.1
Description The issue is related to a DLL hijacking vulnerability in the BIG-IP Edge Client for Windows. Exploitation of this vulnerability may allow an attacker to execute arbitrary commands. User interaction and administrative privileges are required to exploit this vulnerability, as the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path.
Recommendations For versions 7.1.5 through 7.2.3.1, update to a version after 7.2.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the trusted search path to minimize the risk of exploitation. Additionally, avoid running the executable on the system unless necessary, and ensure that administrative privileges are properly secured to prevent unauthorized modifications.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00736
CVE-2023-22283

Produtos afetados

Big-Ip Edge Client