CVE-2024-36495: Read/Write Permissions for Everyone on Configuration File
The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:
C:\ProgramData\WINSelect\WINSelect.wsd
The path for the affected WINSelect Enterprise configuration file is:
C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36495?
CVE-2024-36495 has been assessed as a high severity vulnerability due to improper file permissions allowing unauthorized access.
How do I fix CVE-2024-36495?
To fix CVE-2024-36495, restrict access to the C:\ProgramData\WINSelect\WINSelect.wsd configuration file to authorized users only.
What are the impacts of CVE-2024-36495?
The impacts of CVE-2024-36495 include the potential exposure of sensitive configuration data to unauthorized users.
Which versions of Faronics WINSelect are affected by CVE-2024-36495?
CVE-2024-36495 affects all versions of Faronics WINSelect, both Standard and Enterprise editions.
Is there a workaround for CVE-2024-36495?
A temporary workaround for CVE-2024-36495 is to manually adjust the file permissions of the WINSelect.wsd configuration file.