漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Local privilege escalation in ANSSI’s DFIR-ORC
Vulnerability Description
Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
ANSSI DFIR-ORC 权限许可和访问控制问题漏洞
Vulnerability Description
ANSSI DFIR-ORC是ANSSI公司开源的一款数字取证与事件响应收集工具。 ANSSI DFIR-ORC 10.2.7及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于从共享临时目录加载DLL,可能导致攻击者通过放置恶意DLL并等待应用执行,从而获得管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A