CVE-2023-45159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
05/10/2023
Last modified:
20/05/2025

Description

1E Client installer can perform arbitrary file deletion on protected files.  <br /> <br /> A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. <br /> <br /> A hotfix is available from the 1E support portal that forces the 1E Client to check for a symbolic link or junction and if it finds one refuses to use that path and instead creates a path involving a random GUID.<br /> <br /> for v8.1 use hotfix Q23097<br /> for v8.4 use hotfix Q23105<br /> for v9.0 use hotfix Q23115<br /> <br /> for SaaS customers, use 1EClient v23.7 plus hotfix Q23121

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1e:client:8.1.2.62:*:*:*:*:windows:*:*
cpe:2.3:a:1e:client:8.4.1.159:*:*:*:*:windows:*:*
cpe:2.3:a:1e:client:9.0.1.88:*:*:*:*:windows:*:*
cpe:2.3:a:1e:client:23.7.1.151:*:*:*:*:windows:*:*