PT-2022-22932 · Unknown · Velociraptor
Tim Goddard
·
Published
2022-07-29
·
Updated
2023-07-21
·
CVE-2022-35629
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Velociraptor versions prior to 0.6.5-2
Description
The issue arises from a bug in the communication handling between the client and server, allowing a registered client to send messages claiming to come from another client ID. Additionally, on MacOS and Linux, there is a potential for a symlink attack, where a predictable file name could be replaced with a symlink to another file, allowing the Velociraptor client to overwrite the other file.
Recommendations
For versions prior to 0.6.5-2, update to Velociraptor 0.6.5-2 to resolve the issue. As a temporary workaround, consider restricting access to the client-server communication to minimize the risk of exploitation. On MacOS and Linux, avoid using predictable file names and restrict write access to sensitive files until the issue is resolved.
Fix
Improper Authentication
Link Following
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Velociraptor