漏洞标题
N/A
漏洞描述信息
在IOBit高级系统安全(AscService.exe)15中,一个具有SEImpersonatePrivilege的攻击者可以创建一个与AscService中命名管道名称相同的命名管道。AscService在尝试创建命名管道之前首先尝试连接,因此,在登录时,服务将尝试连接到攻击者,这可能会导致 privileges 的升級(通过令牌操作和ImpersonateNamedPipeClient() )从ADMIN -> SYSTEM 或从本地 Admin -> 域 Admin,具体取决于所使用的用户和命名管道。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the service will try to connect to the attacker which will lead to either escalation of privileges (through token manipulation and ImpersonateNamedPipeClient() ) from ADMIN -> SYSTEM or from Local ADMIN-> Domain ADMIN depending on the user and named pipe that is used.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
IOBit Advanced System Care Free 安全漏洞
漏洞描述信息
IOBit Advanced System Care Free是英国IOBit公司的一款系统管理实用程序。该程序主要用于扫描、修复和优化系统等。 IOBit Advanced System Care Free 15存在安全漏洞。攻击者利用该漏洞升级权限。
CVSS信息
N/A
漏洞类别
其他