CVE-2023-32713 – Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
https://notcve.org/view.php?id=CVE-2023-32713
01 Jun 2023 — In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user. • https://advisory.splunk.com/advisories/SVD-2023-0607 • CWE-269: Improper Privilege Management •
CVE-2023-2598
https://notcve.org/view.php?id=CVE-2023-2598
01 Jun 2023 — This flaw enables full local privilege escalation. • https://github.com/ysanatomic/io_uring_LPE-CVE-2023-2598 • CWE-416: Use After Free CWE-787: Out-of-bounds Write •
CVE-2023-32175 – VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32175
31 May 2023 — VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. An attacker can leverage this vulnerability to ... • https://success.vipre.com/en_US/antivirus-plus-release-notes/home-plus-release-notes-20230530 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2023-32176 – VIPRE Antivirus Plus SetPrivateConfig Directory Traversal Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32176
31 May 2023 — VIPRE Antivirus Plus SetPrivateConfig Directory Traversal Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus SetPrivateConfig Directory Traversal Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus SetPrivateConfig Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. ... An attacker can leverage this vulnerability to escalate privi... • https://success.vipre.com/en_US/antivirus-plus-release-notes/home-plus-release-notes-20230530 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-32177 – VIPRE Antivirus Plus DeleteHistoryFile Directory Traversal Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32177
31 May 2023 — VIPRE Antivirus Plus DeleteHistoryFile Directory Traversal Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus DeleteHistoryFile Directory Traversal Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus DeleteHistoryFile Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. ... An attacker can leverage this vulnerability to escalate pr... • https://success.vipre.com/en_US/antivirus-plus-release-notes/home-plus-release-notes-20230530 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-32178 – VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32178
31 May 2023 — VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. ... An attacker can leverage this vulnerability to escalate privileges and exec... • https://success.vipre.com/en_US/antivirus-plus-release-notes/home-plus-release-notes-20230530 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2023-32179 – VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32179
31 May 2023 — VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. ... An attacker can leverage this vulnerability to escalate privileges and execute... • https://success.vipre.com/en_US/antivirus-plus-release-notes/home-plus-release-notes-20230530 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2023-28080
https://notcve.org/view.php?id=CVE-2023-28080
30 May 2023 — A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. • https://www.dell.com/support/kbdoc/en-us/000214248/dsa-2023-154-powerpath-windows-security-update-for-security-update-for-multiple-vulnerabilities • CWE-427: Uncontrolled Search Path Element •
CVE-2023-28079
https://notcve.org/view.php?id=CVE-2023-28079
30 May 2023 — A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM. • https://www.dell.com/support/kbdoc/en-us/000214248/dsa-2023-154-powerpath-windows-security-update-for-security-update-for-multiple-vulnerabilities • CWE-276: Incorrect Default Permissions •
CVE-2023-32162 – Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-32162
26 May 2023 — Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. An attacker can le... • https://github.com/LucaBarile/ZDI-CAN-16318 • CWE-732: Incorrect Permission Assignment for Critical Resource •