Lucene search

K
ibmIBM2D082A85B2A3654CEC88BEEAFC02CD1C56CAD54705457D8B57B0376ECDAC350A
HistoryJun 26, 2023 - 8:07 p.m.

Security Bulletin: A vulnerability in the IBM Spectrum Protect Backup-Archive Client on Microsoft Windows Workstation operating systems can lead to local user escalated privileges (CVE-2023-28956)

2023-06-2620:07:36
www.ibm.com
23
ibm spectrum protect
backup-archive client
microsoft windows
vulnerability
escalated privileges
access controls

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Summary

A vulnerability in the IBM Spectrum Protect Backup-Archive Client on Microsoft Windows workstation operating systems (Microsoft Windows 8.1, 10, and 11) may allow a local user to escalate their privileges due to improper access controls. This problem does not affect Microsoft Windows server operating systems.

Vulnerability Details

CVEID:CVE-2023-28956
**DESCRIPTION:**IBM Spectrum Protect Backup-Archive Client may allow a local user to escalate their privileges due to improper access controls.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/251767 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 - 8.1.17.2

Remediation/Fixes

Product Fixing level Platform Link to fix and instructions
IBM Storage Protect Backup-Archive Client 8.1.19.0

Microsoft Windows 8.1

Microsoft Windows 10

Microsoft Windows 11

| <https://www.ibm.com/support/pages/node/6989101&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmstorage_protectMatch8.1.0.0
OR
ibmstorage_protectMatch8.1.17.2
OR
ibmspectrum_protectMatch8.1.0.0
OR
ibmspectrum_protectMatch8.1.17.2

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Related for 2D082A85B2A3654CEC88BEEAFC02CD1C56CAD54705457D8B57B0376ECDAC350A