7.8

CVE-2021-43463

Exploit
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ext2 File System Driver ProjectExt2 File System Driver Version0.68 SwPlatformwindows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.356
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-428 Unquoted Search Path or Element

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

https://github.com/M507/Miner
Third Party Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/198746
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/49706
Third Party Advisory
Exploit
VDB Entry