Local Low Privileged Attacker Can Use Untrusted Search Path to Gain Root Privileges
CVE-2024-28133

7.8HIGH

Key Information:

Vendor
CVE Published:
14 May 2024

Summary

A local low privileged attacker can exploit a vulnerability in the CHARX system utility by leveraging an untrusted search path to escalate their privileges to root. This exploitation method poses significant security risks, as it allows unauthorized users to gain elevated access, potentially leading to further system compromises. Organizations using CHARX system utility should assess their systems for vulnerable versions and implement necessary security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

CHARX SEC-3000 0 <= 1.5.1

CHARX SEC-3050 0 <= 1.5.1

CHARX SEC-3100 0 <= 1.5.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trend Micro's Zero Day Initiative
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)
.