ZDI-CAN-23429: ZDI-24-1015: (0Day) Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Hydra Sdk Windows Service. The issue lies in the lack of proper permissions set on a folder created by the service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2024-7245.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23429?
The severity of ZDI-CAN-23429 is considered high due to its potential for privilege escalation by local attackers.
How do I fix ZDI-CAN-23429?
To fix ZDI-CAN-23429, users should apply the latest patches and updates provided by Panda Security for the Dome product.
Who is affected by ZDI-CAN-23429?
Users of Panda Security Dome installations are affected by ZDI-CAN-23429, especially if low-privileged code execution is possible.
What types of attacks can ZDI-CAN-23429 enable?
ZDI-CAN-23429 can enable local privilege escalation attacks, giving attackers elevated rights on the compromised system.
Is ZDI-CAN-23429 easy to exploit?
ZDI-CAN-23429 requires that the attacker first execute low-privileged code, which may vary in difficulty depending on the system security.