CVE-2023-35799: Medium severity Stormshield Endpoint Security vulnerability
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35799?
CVE-2023-35799 refers to the Insecure Permissions vulnerability in Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2.
How does the Insecure Permissions vulnerability in Stormshield Endpoint Security Evolution occur?
The vulnerability occurs when an interactive user utilizes the SES Evolution agent to create arbitrary files with local system privileges, resulting in insecure permissions.
What is the severity of CVE-2023-35799?
The severity of CVE-2023-35799 is medium, with a CVSS score of 5.5.
How can I fix the Insecure Permissions vulnerability in Stormshield Endpoint Security Evolution?
To fix the vulnerability, it is recommended to update Stormshield Endpoint Security Evolution to a version higher than 2.3.2.
Where can I find more information about CVE-2023-35799?
You can find more information about CVE-2023-35799 in the advisories section of the Stormshield website.