netsectuna/CVE-2022-23909

netsectuna/CVE-2022-23909

Releases0
Stars3
Unquoted Service Path privilege escalation vulnerability in Sherpa Connector Service.

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH7.2 HIGH

There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.