PT-2023-16242 · Unknown · Dlp For Windows

Publicado

2023-02-01

·

Atualizado

2023-02-13

·

CVE-2023-0400

CVSS v3.1

8.2

Alta

VetorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DLP for Windows versions 11.9.x
Description The issue allows a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. It is noted that loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.
Recommendations For versions 11.9.x, update to version 11.10.0 to resolve the issue. For versions prior to 11.9, no update is needed as these versions correctly detect and block the attempted upload of sensitive data. As a temporary workaround for version 11.9.x, consider restricting access to web email clients to minimize the risk of exploitation until a patch is applied.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0400

Produtos afetados

Dlp For Windows