PT-2023-30401 · Thegreenbow · Thegreenbow Windows Enterprise Certified Vpn Client+2

CVE-2023-47267

·

Publicado

2023-12-19

·

Atualizado

2025-12-17

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TheGreenBow Windows Enterprise Certified VPN Client version 6.52 TheGreenBow Windows Standard VPN Client version 6.87 TheGreenBow Windows Enterprise VPN Client version 6.87
Description An issue discovered in TheGreenBow VPN clients allows attackers to gain escalated privileges via crafted changes to memory mapped file.
Recommendations For TheGreenBow Windows Enterprise Certified VPN Client version 6.52, consider applying configuration changes to restrict access to memory mapped files until a patch is available. For TheGreenBow Windows Standard VPN Client version 6.87, restrict access to memory mapped files to minimize the risk of exploitation. For TheGreenBow Windows Enterprise VPN Client version 6.87, consider disabling the functionality that allows changes to memory mapped files as a temporary workaround until a patch is available.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-47267

Produtos afetados

Thegreenbow Windows Enterprise Certified Vpn Client
Thegreenbow Windows Enterprise Vpn Client
Thegreenbow Windows Standard Vpn Client