9.8
CVE-2023-47267
- EPSS 0.19%
- Veröffentlicht 19.12.2023 22:15:08
- Zuletzt bearbeitet 17.12.2025 16:55:00
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Thegreenbow ≫ Thegreenbow Vpn Client SwEditionenterprise_certified SwPlatformwindows Version >= 6.52.004 < 6.52.006
Thegreenbow ≫ Thegreenbow Vpn Client SwEditionstandard SwPlatformwindows Version >= 6.87.001 < 6.87.108
Thegreenbow ≫ Thegreenbow Vpn Client SwEditionenterprise SwPlatformwindows Version >= 6.87.001 < 6.87.109
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.41 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.