PT-2022-4063 · Unknown · Velociraptor

·

CVE-2022-35631

·

Published

2022-07-29

·

Updated

2022-08-04

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Velociraptor versions prior to 0.6.5-2
Description The issue is related to incorrect link resolution before accessing a file, which may allow an attacker to overwrite arbitrary files. On MacOS and Linux, it may be possible to perform a symlink attack by replacing a predictable file name with a symlink to another file, allowing the Velociraptor client to overwrite the other file.
Recommendations For versions prior to 0.6.5-2, update to Velociraptor 0.6.5-2 to resolve the issue. As a temporary workaround, consider restricting access to predictable file names that could be exploited for symlink attacks until the update is applied.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04897
CVE-2022-35631

Affected Products

Velociraptor