getcomposer composer-setup 缺省权限不正确

admin 2023-12-01 20:02:40 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
getcomposer composer-setup 缺省权限不正确

CVE编号

CVE-2020-15145

利用情况

暂无

补丁情况

N/A

披露时间

2020-08-15
漏洞描述
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when composer is run by an administrator. 2. A local regular user may create a specially crafted dll in the `C:\ProgramData\ComposerSetup\bin` folder in order to get Local System privileges. See: https://itm4n.github.io/windows-server-netman-dll-hijacking. 3. If the directory of the php.exe selected by the user is not in the system path, it is added without checking that it is admin secured, as per Microsoft guidelines. See: https://msrc-blog.microsoft.com/2018/04/04/triaging-a-dll-planting-vulnerability.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/composer/windows-setup/commit/ca9f1435d368e3377e82d60ef0c7...
https://github.com/composer/windows-setup/security/advisories/GHSA-wgrx-r3qv-332c
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 getcomposer composer-setup * Up to (excluding) 6.0.0
CVSS3评分 8.2
  • 攻击路径 本地
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 已更改
  • 用户交互 需要
  • 可用性 高
  • 保密性 高
  • 完整性 高
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-ID 漏洞类型
CWE-276 缺省权限不正确
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0