Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-23-012
HistoryJan 18, 2023 - 12:00 a.m.

Microsoft Exchange GetTorusCmdletConfigurationEntries Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2023-01-1800:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
24
microsoft exchange
gettoruscmdletconfigurationentries
uncontrolled search path
local privilege escalation
vulnerability
low-privileged code
arbitrary code
system context

EPSS

0.001

Percentile

25.1%

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Exchange. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the GetTorusCmdletConfigurationEntries function. The function loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.