PT-2023-19731 · Vx Search · Vx Search

Publicado

2023-03-16

·

Atualizado

2023-03-22

·

CVE-2023-24671

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VX Search versions 13.8 through 14.7
Description The issue allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file, due to an unquoted service path vulnerability.
Recommendations For versions 13.8 through 14.7, update to a version that fixes the unquoted service path vulnerability to prevent attackers from executing arbitrary commands at elevated privileges.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24671

Produtos afetados

Vx Search