Vulnerability Description
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gimmal | Sherpa Connector Service | 2020.2.20328.2050 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.2032ExploitThird Party AdvisoryVDB Entry
- https://github.com/netsectuna/CVE-2022-23909ExploitThird Party Advisory
- http://packetstormsecurity.com/files/166574/Sherpa-Connector-Service-2020.2.2032ExploitThird Party AdvisoryVDB Entry
- https://github.com/netsectuna/CVE-2022-23909ExploitThird Party Advisory
FAQ
What is CVE-2022-23909?
CVE-2022-23909 is a vulnerability with a CVSS score of 7.8 (HIGH). There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherp...
How severe is CVE-2022-23909?
CVE-2022-23909 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23909?
Check the references section above for vendor advisories and patch information. Affected products include: Gimmal Sherpa Connector Service, Microsoft Windows.