CVE-2023-53947
OCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege Escalation
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
oscinventory · OCS Inventory NGWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →