PT-2023-18643 · Netskope · Netskope Client
Jean-Jamil Khalife
·
Published
2023-06-15
·
Updated
2024-08-22
·
CVE-2023-2270
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netskope client versions prior to R100
Description
The Netskope client service, running with NTSYSTEM privileges, accepts network connections from localhost to start various services and execute commands. A connection handling function in the service uses a relative path to download and unzip configuration files, allowing local users to write arbitrary files in a location accessible only to higher privileged users. This can be exploited by local users to execute code with NTSYSTEM privileges on the end machine.
Recommendations
For versions prior to R100, update to R100 or later to resolve the issue. As a temporary workaround, consider restricting access to the connection handling function to minimize the risk of exploitation. Avoid using the relative path for downloading and unzipping configuration files until the issue is resolved.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netskope Client