7.1

CVE-2023-1486

Exploit

Lespeed WiseCleaner Wise Force Deleter IoControlCode WiseUnlock64.sys 0x220004 access control

A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220004 in the library WiseUnlock64.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223372.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WisecleanerWise Force Deleter Version1.5.3.54
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.394
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
cna@vuldb.com 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
cna@vuldb.com 3.2 3.1 4.9
AV:L/AC:L/Au:S/C:N/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://drive.google.com/file/d/1Ziu1Ut_-01mDpjdj2Z8rfiU7gtUd_WVU/view
Exploit
https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1486
Third Party Advisory
Exploit
https://vuldb.com/?ctiid.223372
Third Party Advisory
Permissions Required
https://vuldb.com/?id.223372
Third Party Advisory
Permissions Required