ZDI-CAN-23005: ZDI-24-1012: (0Day) F-Secure Total Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2024-7240.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23005?
The ZDI-CAN-23005 vulnerability has a high severity rating due to its potential for privilege escalation.
How can I fix ZDI-CAN-23005?
To mitigate ZDI-CAN-23005, ensure that all installations of F-Secure Total are updated to the latest version provided by the vendor.
What type of attack does ZDI-CAN-23005 enable?
ZDI-CAN-23005 enables local attackers to escalate privileges on affected systems.
What is required to exploit ZDI-CAN-23005?
Exploitation of ZDI-CAN-23005 requires user interaction from an administrator.
Which software is impacted by ZDI-CAN-23005?
ZDI-CAN-23005 impacts F-Secure Total installations.