Lucene search

K
cveCertccCVE-2015-2264
HistoryMar 13, 2015 - 1:59 a.m.

CVE-2015-2264

2015-03-1301:59:34
certcc
web.nvd.nist.gov
27
cve
2015
2264
untrusted search path
vulnerabilities
eqatec
analytics
monitor
telerik
privileges
local users
trojan horse
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

26.6%

Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse (a) csunsapi.dll, (b) swift.dll, © nfhwcrhk.dll, or (d) surewarehook.dll file in an unspecified directory.

Affected configurations

Nvd
Node
telerikanalytics_monitor_libraryRange3.2.122
VendorProductVersionCPE
telerikanalytics_monitor_library*cpe:2.3:a:telerik:analytics_monitor_library:*:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

26.6%

Related for CVE-2015-2264