PT-2023-24851 · Move · Move
Published
2023-07-03
·
Updated
2023-07-14
·
CVE-2023-3438
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MOVE versions 4.10.x and earlier
Description
An unquoted Windows search path vulnerability existed in the Windows install service, allowing an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
Recommendations
For MOVE versions 4.10.x and earlier, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the mvagtsce.exe service to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Move