Aller au contenu

Fiche vulnérabilité

CVE-2023-4996 : faille moyenne Netskope Netskope Client (CVSS 6.6)

Description

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 

En bref

Sévérité
Moyenne (CVSS 6.6)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Exploitation active
Non signalée par la CISA
Publication
6 nov. 2023
Dernière mise à jour
5 sept. 2024

Produits concernés

  • Netskope Netskope Client

Correctif et mesures

Netskope patched the issue and released a new version. The issue was fixed in Release101. Customers are recommended to upgrade their client to the versions R101 or greater. Netskope download Instructions – Download Netskope Client and Scripts – Netskope Support https://support.netskope.com/s/article/Download-Netskope-Client-and-Scripts

Preuves de concept publiques

Code tiers non vérifié : à n’exécuter qu’en environnement isolé.

Références

Rechercher une autre vulnérabilité dans la base CVE