CVE-2023-35863

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:madefornet:http_debugger:*:*:*:*:*:*:*:*

History

14 Jul 2023, 15:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-362
CPE cpe:2.3:a:madefornet:http_debugger:*:*:*:*:*:*:*:*
First Time Madefornet http Debugger
Madefornet
References (MISC) https://ctrl-c.club/~blue/nfsdk.html - (MISC) https://ctrl-c.club/~blue/nfsdk.html - Exploit, Technical Description, Third Party Advisory
References (MISC) https://www.michaelrowley.dev/research/posts/nfsdk/nfsdk.html - (MISC) https://www.michaelrowley.dev/research/posts/nfsdk/nfsdk.html - Broken Link
References (MISC) https://www.madefornet.com/products.html - (MISC) https://www.madefornet.com/products.html - Product

05 Jul 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-05 18:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-35863

Mitre link : CVE-2023-35863

CVE.ORG link : CVE-2023-35863


JSON object : View

Products Affected

madefornet

  • http_debugger
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')