2 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code. Un desbordamiento de búfer en Macrium Reflect 8.1.7544 y versiones anteriores permite a los atacantes escalar privilegios o ejecutar código arbitrario. • http://macrium.com https://knowledgebase.macrium.com/display/KNOW80/CVE-2023-43896+Advisory https://northwave-cybersecurity.com/vulnerability-notice/macrium-reflect-driver-out-of-bounds-write • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges. Macrium Reflect incluye un componente OpenSSL que especifica una variable OPENSSLDIR como C:\openssl\. Macrium Reflect contiene un servicio privilegiado que utiliza este componente OpenSSL. • https://www.kb.cert.org/vuls/id/760767 • CWE-284: Improper Access Control CWE-665: Improper Initialization •