PT-2024-22604 · Snowflake · Snowflake Hive Metastore Connector

Gee-Netics

·

Published

2024-03-15

·

Updated

2024-03-17

·

CVE-2024-28851

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snowflake Hive MetaStore Connector (affected versions not specified)
Description The issue concerns a potential elevation of privilege vulnerability in a helper script for the Hive MetaStore Connector. A malicious insider without admin privileges could use the script to download content from a Microsoft domain to the local system and replace the valid content with malicious code. If the attacker then also had local access to the same system where the maliciously modified script is run, they could attempt to manipulate users into executing the attacker-controlled helper script, potentially gaining elevated privileges to the local system.
Recommendations Users who use the helper script are strongly advised to use the latest version as soon as possible. Users unable to upgrade should avoid using the helper script.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28851
GHSA-R68P-G2X9-MQ7X

Affected Products

Snowflake Hive Metastore Connector