Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45755
HistoryMar 05, 2024 - 4:14 a.m.

Privilege Escalation

2024-03-0504:14:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
privilege escalation
vulnerability
app-builder-lib
nsexec
system call
malicious executable

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

15.5%

app-builder-lib is vulnerable to Privilege escalation. The vulnerability is due to NSExec searching the current directory of the installer before searching the system’s PATH when making a system call to open cmd.exe in the .nsh installer script. This flaw allows an attacker to exploit the situation by placing a malicious executable file named cmd.exe in the same folder as the installer, leading to the execution of the malicious file.

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

15.5%