CVE-2023-43766

Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:f-secure:linux_protection:12.0:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:linux_security_64:12.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:f-secure:atlant:1.0.35-1:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:f-secure:client_security:15.00:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:email_and_server_security:15.00:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:server_security:15.00:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:a:f-secure:client_security:15.00:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:24

Type Values Removed Values Added
References () https://www.withsecure.com/en/support/security-advisories - Vendor Advisory () https://www.withsecure.com/en/support/security-advisories - Vendor Advisory
References () https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn4 - Broken Link () https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn4 - Broken Link

25 Sep 2024, 14:35

Type Values Removed Values Added
CWE CWE-269

26 Sep 2023, 14:51

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:f-secure:server_security:15.00:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:email_and_server_security:15.00:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:linux_security_64:12.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:atlant:1.0.35-1:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:client_security:15.00:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:linux_protection:12.0:*:*:*:*:*:*:*
References (MISC) https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn4 - (MISC) https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn4 - Broken Link
References (MISC) https://www.withsecure.com/en/support/security-advisories - (MISC) https://www.withsecure.com/en/support/security-advisories - Vendor Advisory
First Time F-secure client Security
F-secure
F-secure email And Server Security
Apple macos
Apple
F-secure server Security
F-secure atlant
F-secure linux Security 64
Microsoft
F-secure linux Protection
Microsoft windows
Linux
Linux linux Kernel
F-secure elements Endpoint Protection
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

22 Sep 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-22 05:15

Updated : 2024-11-21 08:24


NVD link : CVE-2023-43766

Mitre link : CVE-2023-43766

CVE.ORG link : CVE-2023-43766


JSON object : View

Products Affected

f-secure

  • linux_protection
  • server_security
  • linux_security_64
  • email_and_server_security
  • client_security
  • elements_endpoint_protection
  • atlant

microsoft

  • windows

linux

  • linux_kernel

apple

  • macos
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management