CVE-2024-35288
CVE-2024-35288
Título es
CVE-2024-35288
Mié, 09/10/2024 – 04:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-35288
Descripción en
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.
09/10/2024
09/10/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off
