8.8
CVE-2024-57394
- EPSS 0.4%
- Veröffentlicht 21.04.2025 00:00:00
- Zuletzt bearbeitet 23.06.2025 13:08:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qianxin ≫ Tianqing Endpoint Security Management System Version10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.599 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.