We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-37243



AssignerGoogle
Reserved2023-06-29
Published2023-10-31
Updated2024-09-05

Description

The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.



HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-379: Creation of Temporary File in Directory with Insecure Permissions

Product status

Default status
0x40026412b0

Any version
affected

Credits

Andrew Oliveau, Mandiant 0x4002641310

References

https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0010.md

cve.org CVE-2023-37243

nvd.nist.gov CVE-2023-37243

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-37243
Subscribe to our newsletter to learn more about our work.