ZDI-24-1012: (0Day) F-Secure Total Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2024-7240.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1012?
The severity of ZDI-24-1012 is classified as medium due to its potential to allow local privilege escalation by authenticated users.
How do I fix ZDI-24-1012?
To fix ZDI-24-1012, update your F-Secure Total installation to the latest version provided by F-Secure.
Who is affected by ZDI-24-1012?
ZDI-24-1012 affects installations of F-Secure Total that have the WithSecure plugin hosting service improperly configured.
What is the attack vector for ZDI-24-1012?
The attack vector for ZDI-24-1012 requires local user interaction, specifically from an administrator with access to the affected system.
What are the consequences of exploiting ZDI-24-1012?
Exploiting ZDI-24-1012 allows local attackers to escalate their privileges, potentially gaining higher access to the system.