Lucene search

K
cveMitreCVE-2023-47267
HistoryDec 19, 2023 - 10:15 p.m.

CVE-2023-47267

2023-12-1922:15:08
CWE-269
mitre
web.nvd.nist.gov
20
thegreenbow
vpn client
privilege escalation
memory mapped file
cve-2023-47267
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

39.1%

An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.

Affected configurations

Nvd
Node
thegreenbowwindows_enterprise_certified_vpnMatch6.52
Node
thegreenbowwindows_standard_vpnMatch6.87
Node
thegreenbowwindows_enterprise_vpnMatch6.87
VendorProductVersionCPE
thegreenbowwindows_enterprise_certified_vpn6.52cpe:2.3:a:thegreenbow:windows_enterprise_certified_vpn:6.52:*:*:*:*:*:*:*
thegreenbowwindows_standard_vpn6.87cpe:2.3:a:thegreenbow:windows_standard_vpn:6.87:*:*:*:*:*:*:*
thegreenbowwindows_enterprise_vpn6.87cpe:2.3:a:thegreenbow:windows_enterprise_vpn:6.87:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

39.1%

Related for CVE-2023-47267