Lucene search

K
nvd[email protected]NVD:CVE-2023-4931
HistoryNov 27, 2023 - 2:15 p.m.

CVE-2023-4931

2023-11-2714:15:07
CWE-427
web.nvd.nist.gov
2
plesk installer
uncontrolled path vulnerability
local attacker
arbitrary code execution
dll hijacking

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

23.1%

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

Affected configurations

Nvd
Node
pleskpleskMatch3.27.0.0
VendorProductVersionCPE
pleskplesk3.27.0.0cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

23.1%

Related for NVD:CVE-2023-4931