CVE-2014-2848

MEDIUM

Description

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.

References

http://secunia.com/advisories/57403

http://www.securitytracker.com/id/1029946

https://discussions.nessus.org/thread/7195

https://www.nccgroup.com/en/learning-and-research-centre/technical-advisories/nessus-authenticated-scan-local-privilege-escalation/

Details

Source: MITRE

Published: 2014-04-11

Updated: 2014-04-14

Type: CWE-362

Risk Information

CVSS v2.0

Base Score: 6.9

Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C)

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM