PT-2023-25320 · Stormshield · Stormshield Endpoint Security Evolution

CVE-2023-35799

·

Publicado

2023-06-27

·

Atualizado

2023-07-05

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Stormshield Endpoint Security Evolution versions 2.0.0 through 2.3.2
Description The issue allows an interactive user to create arbitrary files with local system privileges using the SES Evolution agent due to insecure permissions.
Recommendations For versions 2.0.0 through 2.3.2, consider restricting the privileges of the SES Evolution agent to prevent the creation of arbitrary files with local system privileges until a fix is available.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35799

Produtos afetados

Stormshield Endpoint Security Evolution