Lucene search

K
cvelistF-SecureUSCVELIST:CVE-2022-28877
HistoryJul 21, 2022 - 3:32 p.m.

CVE-2022-28877 Local Privilege Escalation Vulnerability in F-Secure & WithSecure Windows Endpoint Products

2022-07-2115:32:45
F-SecureUS
www.cve.org
8
vulnerability
local privilege escalation
f-secure
withsecure
windows endpoint
code execution
security protection bypass

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

EPSS

0

Percentile

5.1%

This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution rights on the victim machine prior to successful exploitation.

CNA Affected

[
  {
    "product": "All F-Secure and WithSecure Endpoint Protection Products for Windows",
    "vendor": "F-Secure and WithSecure",
    "versions": [
      {
        "status": "affected",
        "version": "All Version "
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2022-28877