Improper Link Resolution Vulnerability in HYPR Workforce Access for Windows
CVE-2023-6335

6.4MEDIUM

Key Information:

Vendor

Hypr

Vendor
CVE Published:
16 January 2024

What is CVE-2023-6335?

The vulnerability in HYPR Workforce Access for Windows is characterized by improper link resolution before file access, commonly referred to as 'link following.' This flaw enables attackers to exploit user-controlled filenames, posing potential security risks to systems running affected versions of Workforce Access prior to 8.7. The issue highlights the importance of proper link handling in application security to prevent unauthorized file access.

Affected Version(s)

Workforce Access Windows 0 < 8.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.