4.9
CVE-2014-7298
- EPSS 0.37%
- Veröffentlicht 24.10.2014 10:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Centrify ≫ Directcontrol Version 3.0
Centrify ≫ Directcontrol Version 4.2.0
Centrify ≫ Centrify Suite Version 2008
Centrify ≫ Centrify Suite Version 2012
Centrify ≫ Centrify Suite Version 2012.5
Centrify ≫ Centrify Suite Version 2014.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.289 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:C/I:N/A:N
|
http://twitter.com/travemme/statuses/525298393971564544
http://www.centrify.com/support/announcements.asp#20141014
https://exploithub.com/centrify-data-leakage.html