CVE-2023-36853: Keysight Geolocation Server Exposed Dangerous Method or Function
?In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
Other sources
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Keysight N6854A Geolocation serverto a version that resolves this vulnerability.Fixed in 2.4.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-36853.
What is the severity of CVE-2023-36853?
The severity of CVE-2023-36853 is high with a CVSS score of 7.8.
What is the affected software?
The affected software is Keysight Geolocation Server v2.4.2 and prior.
What is the exploit method for CVE-2023-36853?
The exploit method for CVE-2023-36853 involves a low privileged attacker creating a local ZIP file containing a malicious script in any location to load a DLL with SYSTEM privileges.
How can I fix CVE-2023-36853?
To fix CVE-2023-36853, it is recommended to update to a version later than v2.4.2 of Keysight Geolocation Server.