CVE-2024-36495
CVSS V2 None
CVSS V3 None
Description
The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:
C:\ProgramData\WINSelect\WINSelect.wsd
The path for the affected WINSelect Enterprise configuration file is:
C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
Overview
- CVE ID
- CVE-2024-36495
- Assigner
- SEC-VLab
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-24T08:50:07.161Z
- Last Modified Date
- 2024-06-24T08:50:07.161Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://r.sec-consult.com/winselect | third-party-advisory |
https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes | release-notes |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-36495 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36495 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 18:44:53 | Added to TrackCVE |