CVE-2023-28141 Vulnerability Details

  /     /     /  

CVE-2023-28141 Metadata Quick Info

CVE Published: 18/04/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: Qualys | Vendor: Qualys | Product: Cloud Agent
Status : PUBLISHED

CVE-2023-28141 Description

An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or otherwise on unauthorized files, allowing for the potential modification or deletion of sensitive files limited only to that specific directory/file object. This vulnerability is bounded to the time of installation/uninstallation and can only be exploited locally. At the time of this disclosure, versions before 4.0 are classified as End of Life.

Metrics

CVSS Version: 3.1 | Base Score: 6.7 MEDIUM
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-59
CWE Name: CWE-59 Improper Link Resolution Before File Access ( Link Following )
Source: Qualys

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-132
CAPEC Description: CAPEC-132 Symlink Attack


Source: NVD (National Vulnerability Database).