CVE-2024-36495

The application Faronics WINSelect (Standard + Enterprise)saves its configuration in an encrypted file on the file systemwhich "Everyone" has read and write access to, path to file:



C:\ProgramData\WINSelect\WINSelect.wsd

The path forthe affected WINSelect Enterpriseconfiguration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SEC-VLabCNA
---
---
CISA-ADPADP
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---