Lucene search

K
nvd[email protected]NVD:CVE-2023-5937
HistoryMay 15, 2024 - 4:15 p.m.

CVE-2023-5937

2024-05-1516:15:09
CWE-538
web.nvd.nist.gov
2
windows systems
arc configuration files
world-readable
vulnerability
disclosure
local attackers
sensitive data
exfiltration

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

3.9

Confidence

High

EPSS

0

Percentile

9.0%

On Windows systems, the Arc configuration files resulted to be world-readable.

This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

3.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-5937