PT-2022-4063 · Unknown · Velociraptor

Tim Goddard

·

Published

2022-07-29

·

Updated

2022-08-04

·

CVE-2022-35631

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Velociraptor versions prior to 0.6.5-2
Description The issue is related to incorrect link resolution before accessing a file, which may allow an attacker to overwrite arbitrary files. On MacOS and Linux, it may be possible to perform a symlink attack by replacing a predictable file name with a symlink to another file, allowing the Velociraptor client to overwrite the other file.
Recommendations For versions prior to 0.6.5-2, update to Velociraptor 0.6.5-2 to resolve the issue. As a temporary workaround, consider restricting access to predictable file names that could be exploited for symlink attacks until the update is applied.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BDU:2022-04897
CVE-2022-35631

Affected Products

Velociraptor