ZeroHour

CVE-2023-35863

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p19
Published
()
Modified
Description

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

Vendors
madefornet
Products
http debugger
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.