← Back

CVE-2023-4996

nvd nist
Published: Nov 6, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

Affected (1)

Products: Netskope: Netskope
1 product
Netskope
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 101
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.