PT-2024-28012 · Unknown+1 · Prunsrv.Exe+1

Lukas Krieg

·

Published

2024-09-02

·

Updated

2024-09-07

·

CVE-2024-38456

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HIGH-LEIT versions 04.25.00.00 through 04.25.01.01 HIGH-LEIT version 05.08.01.03
Description The issue concerns an insecure file and folder permissions vulnerability in the prunsrv.exe file. This vulnerability can be exploited by a regular user to escalate privileges and execute arbitrary code in the context of NT AUTHORITYSYSTEM.
Recommendations For HIGH-LEIT versions 04.25.00.00 through 04.25.01.01, consider restricting access to the prunsrv.exe file until a patch is available. For HIGH-LEIT version 05.08.01.03, consider restricting access to the prunsrv.exe file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38456

Affected Products

High-Leit
Prunsrv.Exe