PT-2022-16327 · Sherpa · Sherpa Connector Service
Fumenoid
+2
·
Published
2022-04-05
·
Updated
2022-04-12
·
CVE-2022-23909
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sherpa Connector Service version 2020.2.20328.2050
Description
The issue is related to an unquoted service path in the Sherpa Connector Service, which could allow a local user to escalate privileges. This can be achieved by creating a specific file, for example, "C:Program FilesSherpa SoftwareSherpa.exe".
Recommendations
For version 2020.2.20328.2050, consider updating to a newer version that quotes the service path to prevent privilege escalation. As a temporary workaround, restrict access to the
SherpaConnectorService.exe to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sherpa Connector Service