PT-2023-20971 · Tsplus · Tsplus Remote Work

Published

2023-10-17

·

Updated

2023-10-24

·

CVE-2023-27133

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TSplus Remote Work version 16.0.0.0
Description The issue is related to weak permissions for certain file types, including .exe, .js, and .html files, located under the %PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder. This weakness may enable privilege escalation if a different user can modify these files.
Recommendations For TSplus Remote Work version 16.0.0.0, consider restricting access to the %PROGRAMFILES(X86)%TSplus-RemoteWorkClientswww folder to prevent unauthorized modifications to .exe, .js, and .html files until a patch is available.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-27133

Affected Products

Tsplus Remote Work