There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.20328.2050-Unquoted-Service-Path.html | Exploit Third Party Advisory VDB Entry |
https://github.com/netsectuna/CVE-2022-23909 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-04-04 23:15
Updated : 2022-04-12 13:58
NVD link : CVE-2022-23909
Mitre link : CVE-2022-23909
JSON object : View
CWE
CWE-428
Unquoted Search Path or Element
Products Affected
gimmal
- sherpa_connector_service
microsoft
- windows