CVE-2024-40872
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2024
Last modified:
26/07/2024
Description
There is an elevation of privilege vulnerability in server<br />
and client components of Absolute Secure Access prior to version 13.07.<br />
Attackers with local access and valid desktop user credentials can elevate<br />
their privilege to system level by passing invalid address data to the vulnerable<br />
component. This could be used to<br />
manipulate process tokens to elevate the privilege of a normal process to<br />
System. The scope is changed, the impact to system confidentiality and<br />
integrity is high, the impact to the availability of the effected component is<br />
none.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH



