Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Client
CVE-2023-38402

7.1HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
15 August 2023

Summary

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client allows unauthorized users to overwrite files with SYSTEM-level privileges. An attacker exploiting this vulnerability could potentially trigger a Denial-of-Service condition that disrupts the Microsoft Windows operating system boot process, leading to significant operational disruptions. Organizations using the affected VIA client should review their systems for potential exploitation risks and follow best practices to mitigate this vulnerability.

Affected Version(s)

HPE Aruba Networking Virtual Intranet Access (VIA) Windows HPE Aruba Networking Virtual Intranet Access (VIA) client for Microsoft Windows

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gee-netics
.