PT-2023-22438 · Syncapp · Syncapp
Published
2023-05-22
·
Updated
2023-05-27
·
CVE-2023-29838
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SyncApp version 19.0.3.0
Description
The issue is related to an Insecure Permission vulnerability that allows a local attacker to escalate privileges. This is achieved via the SyncService.exe file.
Recommendations
For SyncApp version 19.0.3.0, consider restricting access to the SyncService.exe file as a temporary mitigation measure until a patch is available.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syncapp