CVE-2023-38402: Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Client
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38402?
CVE-2023-38402 is a vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client that could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM.
How does CVE-2023-38402 impact Microsoft Windows?
CVE-2023-38402 could create a Denial-of-Service (DoS) condition affecting Microsoft Windows.
What is the severity level of CVE-2023-38402?
CVE-2023-38402 has a severity level of 7.1 (high).
What software is affected by CVE-2023-38402?
The HPE Aruba Networking Virtual Intranet Access (VIA) client version up to and exclusive of 4.5.0 is affected.
How can I fix CVE-2023-38402?
To fix CVE-2023-38402, update your HPE Aruba Networking Virtual Intranet Access (VIA) client to a version beyond 4.5.0.