Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.netskope.com/company/security-compliance-and-assurance/security-advisories-and-disclosures/netskope-security-advisory-nskpsa-2023-003 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.6 |
14 Nov 2023, 17:04
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netskope:netskope:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
CWE | CWE-281 | |
References | (MISC) https://www.netskope.com/company/security-compliance-and-assurance/security-advisories-and-disclosures/netskope-security-advisory-nskpsa-2023-003 - Vendor Advisory | |
First Time |
Microsoft windows
Netskope netskope Netskope Microsoft |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
06 Nov 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-06 11:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4996
Mitre link : CVE-2023-4996
CVE.ORG link : CVE-2023-4996
JSON object : View
Products Affected
netskope
- netskope
microsoft
- windows
CWE
CWE-281
Improper Preservation of Permissions