First published: Mon Sep 11 2023(Updated: )
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
N-able Take Control | <7.0.43 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27470 is a vulnerability in N-able Take Control Agent that allows arbitrary file deletion through a TOCTOU race condition.
CVE-2023-27470 has a severity rating of 7 out of 10, indicating a high severity.
N-able Take Control Agent versions up to and including 7.0.41.1141 before 7.0.43 are affected by CVE-2023-27470.
CVE-2023-27470 can be exploited by leveraging a TOCTOU race condition using a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates to delete arbitrary files.
No, Microsoft Windows is not vulnerable to CVE-2023-27470.