CVE-2024-40872

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2024
Last modified:
26/07/2024

Description

There is an elevation of privilege vulnerability in server<br /> and client components of Absolute Secure Access prior to version 13.07.<br /> Attackers with local access and valid desktop user credentials can elevate<br /> their privilege to system level by passing invalid address data to the vulnerable<br /> component. This could be used to<br /> manipulate process tokens to elevate the privilege of a normal process to<br /> System. The scope is changed, the impact to system confidentiality and<br /> integrity is high, the impact to the availability of the effected component is<br /> none.