There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.20328.2050-Unquoted-Service-Path.html | Exploit Third Party Advisory VDB Entry |
https://github.com/netsectuna/CVE-2022-23909 | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.20328.2050-Unquoted-Service-Path.html | Exploit Third Party Advisory VDB Entry |
https://github.com/netsectuna/CVE-2022-23909 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.20328.2050-Unquoted-Service-Path.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://github.com/netsectuna/CVE-2022-23909 - Exploit, Third Party Advisory |
Information
Published : 2022-04-05 06:15
Updated : 2024-11-21 06:49
NVD link : CVE-2022-23909
Mitre link : CVE-2022-23909
CVE.ORG link : CVE-2022-23909
JSON object : View
Products Affected
microsoft
- windows
gimmal
- sherpa_connector_service
CWE
CWE-428
Unquoted Search Path or Element