ZDI-25-984: Alibaba Cloud Workspace Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Alibaba Cloud Workspace Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-984?
The vulnerability ZDI-25-984 has been assigned a critical severity level due to its potential for privilege escalation.
How do I fix ZDI-25-984?
To fix ZDI-25-984, ensure that your Alibaba Cloud Workspace Client is updated to the latest version provided by the vendor.
Who is affected by ZDI-25-984?
ZDI-25-984 affects any installations of Alibaba Cloud Workspace Client that have not been patched against this vulnerability.
What type of attack does ZDI-25-984 enable?
ZDI-25-984 enables local attackers to escalate their privileges on the affected systems.
What must an attacker do to exploit ZDI-25-984?
An attacker must first execute low-privileged code on the target system to exploit the vulnerability ZDI-25-984.