漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the invoking process (in this case, granting Authenticated Users full access over the target file). This vulnerability can be triggered by a low-privileged user to perform DLL Hijacking/Binary Planting attacks and ultimately execute code as NT AUTHORITY\SYSTEM with the help of Symbolic Links.
漏洞信息
N/A
漏洞
N/A
漏洞
Netwrix Auditor 权限许可和访问控制问题漏洞
漏洞信息
Netwrix Auditor是美国Netwrix公司的一套IT审计软件。该软件具有用户行为分析、安全威胁主动检测和威胁类型警报等功能。 Netwrix Auditor 9.8之前版本中存在安全漏洞,该漏洞源于程序为%PROGRAMDATA%Netwrix AuditorLogsActiveDirectory和子文件夹分配了不安全的权限并且Netwrix.ADA.StorageAuditService服务没有执行正确的模拟。攻击者可利用该漏洞以NT AUTHORITYSYSTEM权限执行代码。
漏洞信息
N/A
漏洞
N/A