CVE-2024-7240

F-Secure Total Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23005.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:f-secure:total:19.2:*:*:*:*:*:*:*

History

11 Dec 2024, 14:22

Type Values Removed Values Added
CPE cpe:2.3:a:f-secure:total:19.2:*:*:*:*:*:*:*
First Time F-secure total
F-secure
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.8
Summary
  • (es) Vulnerabilidad de escalada de privilegios locales en F-Secure Total Link Following. Esta vulnerabilidad permite a los atacantes locales escalar privilegios en las instalaciones afectadas de F-Secure Total. Se requiere la interacción del usuario por parte de un administrador para explotar esta vulnerabilidad. La falla específica existe dentro del servicio de alojamiento de complementos WithSecure. Al crear un enlace simbólico, un atacante puede abusar del servicio para crear un archivo. Un atacante puede aprovechar esta vulnerabilidad para escalar privilegios y ejecutar código arbitrario en el contexto de SYSTEM. Era ZDI-CAN-23005.
References () https://www.zerodayinitiative.com/advisories/ZDI-24-1012/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-1012/ - Third Party Advisory

22 Nov 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 22:15

Updated : 2024-12-11 14:22


NVD link : CVE-2024-7240

Mitre link : CVE-2024-7240

CVE.ORG link : CVE-2024-7240


JSON object : View

Products Affected

f-secure

  • total
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')