CVE-2023-5937: Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0
Published May 15, 2024
·Updated
On Windows systems, the Arc configuration files resulted to be world-readable.
This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
Affected Software
1 affected component
arc arc<1.6.0
Remediation
Information
Upgrade to v1.6.0 or later.
Event History
May 15, 2024
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-5937?
CVE-2023-5937 is rated as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2023-5937?
To fix CVE-2023-5937, ensure that the Arc configuration files are set to restrict access, making them non-world-readable.
3
What type of data is at risk with CVE-2023-5937?
CVE-2023-5937 allows local attackers to exfiltrate sensitive data from the world-readable Arc configuration files.
4
Which versions are affected by CVE-2023-5937?
CVE-2023-5937 affects Arc versions prior to 1.6.0.
5
Can local users exploit CVE-2023-5937?
Yes, local users can exploit CVE-2023-5937 to gain unauthorized access to sensitive configuration data.