PT-2023-20971 · Tsplus · Tsplus Remote Work

CVE-2023-27133

·

Publicado

2023-10-17

·

Atualizado

2023-10-24

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TSplus Remote Work version 16.0.0.0
Description The issue is related to weak permissions for certain file types, including .exe, .js, and .html files, located under the %PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder. This weakness may enable privilege escalation if a different user can modify these files.
Recommendations For TSplus Remote Work version 16.0.0.0, consider restricting access to the %PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder to prevent unauthorized modifications to .exe, .js, and .html files until a patch is available.

Exploit

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27133

Produtos afetados

Tsplus Remote Work