PT-2023-18789 · Unknown · Shibboleth Service Provider

Published

2023-01-11

·

Updated

2025-04-07

·

CVE-2023-22947

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shibboleth Service Provider (SP) versions prior to 3.4.1
Description The issue concerns insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP). This allows an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. The vulnerability occurs because the installation goes under C:opt by default, rather than C:Program Files. The vendor disputes the significance of this report, stating that the ACLs are considered a best effort thing and it was a documentation mistake.
Recommendations For versions prior to 3.4.1, update to version 3.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable folder to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2023-22947

Affected Products

Shibboleth Service Provider