Advertisement






VX Search 13.8 Unquoted Service Path

CVE Category Price Severity
CVE-2023-24671 CWE-428 $1500 High
Author Risk Exploitation Type Date
Unknown High Local 2023-03-12
CPE
cpe:cpe:/a:binarytree:vx-search:13.8
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.149998 0.99213

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023030028

Below is a copy:

VX Search 13.8 Unquoted Service Path
Executive Summary:

Product Name: VX Search
Vendor Home Page:  https://www.vxsearch.com/
Affected Version(s): VX Search v13.8
Fixed Version: all versions later v13.8
Vulnerability Type: Unquoted Search Path (CWE-428)
CVE Reference: CVE-2023-24671
Credit: Thurein Soe


Vendor Description:

VX Search is an automated, rule-based file search solution allowing one to
search files by file type, category, file name, size, location, extension,
regular expressions, text and binary patterns.

Vulnerability description:
VX Search v13.8 was discovered to contain an unquoted service path
vulnerability which allows attackers to execute arbitrary commands.
However, this could not lead to a fully local privilege escalation attack.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum