7.8

CVE-2022-38176

An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer package for the Client V3 services, allowing for local user privilege escalation by overwriting the executable file via an alternative data stream. NOTE: this is not the same as CVE-2021-31859.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ysoft ≫ Safeq Version 6.0 Update -
Ysoft ≫ Safeq Version 6.0 Update build32
Ysoft ≫ Safeq Version 6.0 Update build33
Ysoft ≫ Safeq Version 6.0 Update build34
Ysoft ≫ Safeq Version 6.0 Update build35
Ysoft ≫ Safeq Version 6.0 Update build36
Ysoft ≫ Safeq Version 6.0 Update build37
Ysoft ≫ Safeq Version 6.0 Update build38
Ysoft ≫ Safeq Version 6.0 Update build39
Ysoft ≫ Safeq Version 6.0 Update build40
Ysoft ≫ Safeq Version 6.0 Update build41
Ysoft ≫ Safeq Version 6.0 Update build42
Ysoft ≫ Safeq Version 6.0 Update build43
Ysoft ≫ Safeq Version 6.0 Update build44
Ysoft ≫ Safeq Version 6.0 Update build45
Ysoft ≫ Safeq Version 6.0 Update build46
Ysoft ≫ Safeq Version 6.0 Update build47
Ysoft ≫ Safeq Version 6.0 Update build48
Ysoft ≫ Safeq Version 6.0 Update build49
Ysoft ≫ Safeq Version 6.0 Update build50
Ysoft ≫ Safeq Version 6.0 Update build51
Ysoft ≫ Safeq Version 6.0 Update build52
Ysoft ≫ Safeq Version 6.0 Update build53
Ysoft ≫ Safeq Version 6.0 Update build54
Ysoft ≫ Safeq Version 6.0 Update build55
Ysoft ≫ Safeq Version 6.0 Update build56
Ysoft ≫ Safeq Version 6.0 Update build57
Ysoft ≫ Safeq Version 6.0 Update build58
Ysoft ≫ Safeq Version 6.0 Update build59
Ysoft ≫ Safeq Version 6.0 Update build60
Ysoft ≫ Safeq Version 6.0 Update build61
Ysoft ≫ Safeq Version 6.0 Update build62
Ysoft ≫ Safeq Version 6.0 Update build63
Ysoft ≫ Safeq Version 6.0 Update build64
Ysoft ≫ Safeq Version 6.0 Update build65
Ysoft ≫ Safeq Version 6.0 Update build66
Ysoft ≫ Safeq Version 6.0 Update build67
Ysoft ≫ Safeq Version 6.0 Update build68
Ysoft ≫ Safeq Version 6.0 Update build69
Ysoft ≫ Safeq Version 6.0 Update build70
Ysoft ≫ Safeq Version 6.0 Update build71
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.ysoft.com/en/legal/ysoft-safeq-client-v3-local-privilege-escalation
Vendor Advisory
https://ysoft.com
Vendor Advisory