Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Netsectuna

#32073of 53,608
7.8Total CVSS
Vulnerabilities · 1
PT-2022-16327
7.8
2022-04-05
Sherpa · Sherpa Connector Service · CVE-2022-23909
**Name of the Vulnerable Software and Affected Versions** Sherpa Connector Service version 2020.2.20328.2050 **Description** The issue is related to an unquoted service path in the Sherpa Connector Service, which could allow a local user to escalate privileges. This can be achieved by creating a specific file, for example, "C:Program FilesSherpa SoftwareSherpa.exe". **Recommendations** For version 2020.2.20328.2050, consider updating to a newer version that quotes the service path to prevent privilege escalation. As a temporary workaround, restrict access to the `SherpaConnectorService.exe` to minimize the risk of exploitation.