CVE-2024-36495
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2024
Last modified:
15/04/2026
Description
The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:<br />
<br />
<br />
<br />
C:\ProgramData\WINSelect\WINSelect.wsd<br />
<br />
The path for the affected WINSelect Enterprise configuration file is:<br />
<br />
C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2024/Jun/12
- https://r.sec-consult.com/winselect
- https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes
- http://seclists.org/fulldisclosure/2024/Jun/12
- https://r.sec-consult.com/winselect
- https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes


