PT-2023-19731 · Vx Search · Vx Search
Publicado
2023-03-16
·
Atualizado
2023-03-22
·
CVE-2023-24671
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VX Search versions 13.8 through 14.7
Description
The issue allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file, due to an unquoted service path vulnerability.
Recommendations
For versions 13.8 through 14.7, update to a version that fixes the unquoted service path vulnerability to prevent attackers from executing arbitrary commands at elevated privileges.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vx Search