CVE-2023-7270

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.
Configurations

No configuration.

History

21 Nov 2024, 08:45

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jul/5 - () http://seclists.org/fulldisclosure/2024/Jul/5 -
References () https://r.sec-consult.com/softmaker - () https://r.sec-consult.com/softmaker -
References () https://softmaker.de/download/servicepacks - () https://softmaker.de/download/servicepacks -
References () https://www.freeoffice.com/de/download/servicepacks - () https://www.freeoffice.com/de/download/servicepacks -

01 Aug 2024, 13:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-266

04 Jul 2024, 07:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/5 -

27 Jun 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en SoftMaker Office 2024/NX antes de la revisión 1214 y SoftMaker FreeOffice 2014 antes de la revisión 1215. FreeOffice 2021 también se ve afectado, pero no se solucionará. Se descubrió que los archivos de instalación de SoftMaker Office y FreeOffice MSI producían una ventana visible de conhost.exe ejecutándose como el usuario de SYSTEM cuando se utiliza la función de reparación de msiexec.exe.Esto permite a un atacante local con pocos privilegios utilizar una cadena de acciones para abrir un cmd.exe completamente funcional con los privilegios del usuario de SYSTEM.

27 Jun 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 10:15

Updated : 2024-11-21 08:45


NVD link : CVE-2023-7270

Mitre link : CVE-2023-7270

CVE.ORG link : CVE-2023-7270


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment