ZDI-CAN-26635: ZDI-25-984: Alibaba Cloud Workspace Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Alibaba Cloud Workspace Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26635?
ZDI-CAN-26635 has been assigned a high severity rating due to its potential for privilege escalation.
How does ZDI-CAN-26635 affect Alibaba Cloud Workspace Client?
ZDI-CAN-26635 allows local attackers to escalate privileges on affected installations of Alibaba Cloud Workspace Client.
What are the prerequisites for exploiting ZDI-CAN-26635?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-26635.
How can I mitigate ZDI-CAN-26635?
To mitigate ZDI-CAN-26635, update Alibaba Cloud Workspace Client to the latest version provided by Alibaba.
Who is affected by ZDI-CAN-26635?
Users and administrators of affected installations of Alibaba Cloud Workspace Client are at risk from ZDI-CAN-26635.