7.8
CVE-2023-43766
- EPSS 0.15%
- Veröffentlicht 22.09.2023 05:15:09
- Zuletzt bearbeitet 21.11.2024 08:24:44
- Erkennungen
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F-secure ≫ Linux Protection Version 12.0
F-secure ≫ Linux Security 64 Version 12.0
F-secure ≫ Client Security Version 15.00
F-secure ≫ Elements Endpoint Protection Version >= 17.0
F-secure ≫ Email And Server Security Version 15.00
F-secure ≫ Server Security Version 15.00
F-secure ≫ Client Security Version 15.00
F-secure ≫ Elements Endpoint Protection Version >= 17.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.046 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://www.withsecure.com/en/support/security-advisories
https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn4