PT-2023-20971 · Tsplus · Tsplus Remote Work
CVE-2023-27133
·
Publicado
2023-10-17
·
Atualizado
2023-10-24
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TSplus Remote Work version 16.0.0.0
Description
The issue is related to weak permissions for certain file types, including
.exe, .js, and .html files, located under the %PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder. This weakness may enable privilege escalation if a different user can modify these files.Recommendations
For TSplus Remote Work version 16.0.0.0, consider restricting access to the
%PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder to prevent unauthorized modifications to .exe, .js, and .html files until a patch is available.Exploit
Correção
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tsplus Remote Work