CVE-2023-49147

An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pdf24:pdf24_creator:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:32

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/176206/PDF24-Creator-11.15.1-Local-Privilege-Escalation.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/176206/PDF24-Creator-11.15.1-Local-Privilege-Escalation.html - Exploit, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2023/Dec/18 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2023/Dec/18 - Exploit, Mailing List, Third Party Advisory
References () https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/ - Exploit, Third Party Advisory () https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/ - Exploit, Third Party Advisory

02 Jan 2024, 14:26

Type Values Removed Values Added
CPE cpe:2.3:a:pdf24:pdf24_creator:*:*:*:*:*:*:*:*
References () http://packetstormsecurity.com/files/176206/PDF24-Creator-11.15.1-Local-Privilege-Escalation.html - () http://packetstormsecurity.com/files/176206/PDF24-Creator-11.15.1-Local-Privilege-Escalation.html - Exploit, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2023/Dec/18 - () http://seclists.org/fulldisclosure/2023/Dec/18 - Exploit, Mailing List, Third Party Advisory
References () https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/ - () https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/ - Exploit, Third Party Advisory
Summary
  • (es) Se descubrió un problema en PDF24 Creator 11.14.0. Se descubrió que la configuración del archivo de instalación msi produce una ventana cmd.exe visible cuando se utiliza la función de reparación de msiexec.exe. Esto permite a un atacante local sin privilegios utilizar una cadena de acciones (por ejemplo, un bloqueo de operación en faxPrnInst.log) para abrir un cmd.exe de SYSTEM.
CWE NVD-CWE-noinfo
First Time Pdf24
Pdf24 pdf24 Creator
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

19 Dec 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-19 23:15

Updated : 2024-11-21 08:32


NVD link : CVE-2023-49147

Mitre link : CVE-2023-49147

CVE.ORG link : CVE-2023-49147


JSON object : View

Products Affected

pdf24

  • pdf24_creator