CVE-2023-36853
19.07.2023, 22:15
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.Enginsight
Vendor | Product | Version |
---|---|---|
keysight | geolocation_server | 𝑥 ≤ 2.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-749 - Exposed Dangerous Method or FunctionThe software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
- CWE-427 - Uncontrolled Search Path ElementThe product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.