Advertisement






VX Search 13.8 Unquoted Service Path

CVE Category Price Severity
CVE-2023-24671 CWE-428 $1500 High
Author Risk Exploitation Type Date
Unknown High Local 2023-03-12
CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023030028

Below is a copy:

VX Search 13.8 Unquoted Service Path
Executive Summary:

Product Name: VX Search
Vendor Home Page:  https://www.vxsearch.com/
Affected Version(s): VX Search v13.8
Fixed Version: all versions later v13.8
Vulnerability Type: Unquoted Search Path (CWE-428)
CVE Reference: CVE-2023-24671
Credit: Thurein Soe


Vendor Description:

VX Search is an automated, rule-based file search solution allowing one to
search files by file type, category, file name, size, location, extension,
regular expressions, text and binary patterns.

Vulnerability description:
VX Search v13.8 was discovered to contain an unquoted service path
vulnerability which allows attackers to execute arbitrary commands.
However, this could not lead to a fully local privilege escalation attack.

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.