漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite
Vulnerability Description
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
N/A
Vulnerability Title
Cloud Foundry bosh-windows-stemcell-builder 权限许可和访问控制问题漏洞
Vulnerability Description
Cloud Foundry bosh-windows-stemcell-builder是美国Cloud Foundry组织的一款Windows Stemcell构建工具。 Cloud Foundry bosh-windows-stemcell-builder 2019.98之前版本存在权限许可和访问控制问题漏洞,该漏洞源于BOSH.Utils.psm1中权限分配不正确,允许低权限认证用户覆盖C:\bosh\service_wrapper.exe或C:\bosh\bosh-agent.exe文件,并在下次服
CVSS Information
N/A
Vulnerability Type
N/A