Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Client
CVE-2023-38402
7.1HIGH
Summary
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client allows unauthorized users to overwrite files with SYSTEM-level privileges. An attacker exploiting this vulnerability could potentially trigger a Denial-of-Service condition that disrupts the Microsoft Windows operating system boot process, leading to significant operational disruptions. Organizations using the affected VIA client should review their systems for potential exploitation risks and follow best practices to mitigate this vulnerability.
Affected Version(s)
HPE Aruba Networking Virtual Intranet Access (VIA) Windows HPE Aruba Networking Virtual Intranet Access (VIA) client for Microsoft Windows
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gee-netics