CVE-2023-50702

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.
Configurations

No configuration.

History

21 Nov 2024, 08:37

Type Values Removed Values Added
References () https://www.youtube.com/watch?v=3dCoV33y1WY - () https://www.youtube.com/watch?v=3dCoV33y1WY -

08 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

27 Mar 2024, 12:29

Type Values Removed Values Added
Summary
  • (es) Sikka SSCWindowsService 5 2023-09-14 ejecuta un programa como LocalSystem pero permite el control total por parte de usuarios con pocos privilegios (y los usuarios con pocos privilegios tienen acceso de escritura a %PROGRAMDATA%\SSCService). En consecuencia, los usuarios con pocos privilegios pueden ejecutar código arbitrario como LocalSystem.

26 Mar 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 23:15

Updated : 2024-11-21 08:37


NVD link : CVE-2023-50702

Mitre link : CVE-2023-50702

CVE.ORG link : CVE-2023-50702


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control