CVE-2023-27470: Race Condition
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportServiceN-Central\PushUpdates, leading to arbitrary file deletion.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27470?
CVE-2023-27470 is a vulnerability in N-able Take Control Agent that allows arbitrary file deletion through a TOCTOU race condition.
How severe is CVE-2023-27470?
CVE-2023-27470 has a severity rating of 7 out of 10, indicating a high severity.
Which software is affected by CVE-2023-27470?
N-able Take Control Agent versions up to and including 7.0.41.1141 before 7.0.43 are affected by CVE-2023-27470.
How can CVE-2023-27470 be exploited?
CVE-2023-27470 can be exploited by leveraging a TOCTOU race condition using a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates to delete arbitrary files.
Is Microsoft Windows vulnerable to CVE-2023-27470?
No, Microsoft Windows is not vulnerable to CVE-2023-27470.