CVE-2023-2270: Local privilege escalation
The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope client before R100 in this service utilized a relative path to download and unzip configuration files on the machine. This relative path provided a way for local users to write arbitrary files at a location which is accessible to only higher privileged users. This can be exploited by local users to execute code with NT\SYSTEM privileges on the end machine.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2270?
The severity of CVE-2023-2270 is high with a CVSS score of 7.8.
What is the affected software for CVE-2023-2270?
The affected software for CVE-2023-2270 is Netskope client version up to R100.
What is the description of CVE-2023-2270?
CVE-2023-2270 is a vulnerability in the Netskope client service that allows network connections from localhost to start services and execute commands.
How can I fix CVE-2023-2270?
To fix CVE-2023-2270, it is recommended to update to a version of Netskope client R100 or higher.
Are Microsoft Windows systems vulnerable to CVE-2023-2270?
No, Microsoft Windows systems are not vulnerable to CVE-2023-2270.