Lucene search

K
nvd[email protected]NVD:CVE-2023-22947
HistoryJan 11, 2023 - 2:15 a.m.

CVE-2023-22947

2023-01-1102:15:11
CWE-427
web.nvd.nist.gov
3
windows
shibboleth service provider
insecure folder permissions
privilege escalation
dll planting

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable’s folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that “We consider the ACLs a best effort thing” and “it was a documentation mistake.”

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
shibbolethservice_providerRange<3.4.1
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
shibbolethservice_provider*cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2023-22947