Insecure Permissions in Stormshield Endpoint Security by Stormshield
CVE-2023-35799

5.5MEDIUM

Key Information:

Vendor
CVE Published:
27 June 2023

What is CVE-2023-35799?

Stormshield Endpoint Security Evolution versions 2.0.0 through 2.3.2 are prone to a vulnerability that allows an interactive user to leverage the SES Evolution agent to create arbitrary files with local system privileges. This lack of proper permission controls could enable malicious actions, compromising system integrity and data confidentiality.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.