Vulnerability CVE-2023-35863


Published: 2023-07-05

Description:
In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

 References:
https://www.michaelrowley.dev/research/posts/nfsdk/nfsdk.html
https://ctrl-c.club/~blue/nfsdk.html
https://www.madefornet.com/products.html

Copyright 2026, cxsecurity.com

 

Back to Top