Vulnerability CVE-2022-23909


Published: 2022-04-05

Description:
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Sherpa Connector Service 2020.2.20328.2050 Unquoted Service Path
Harshit
04.04.2022

Type:

CWE-428

(Unquoted Search Path or Element)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.20328.2050-Unquoted-Service-Path.html
https://github.com/netsectuna/CVE-2022-23909

Copyright 2024, cxsecurity.com

 

Back to Top