CVE-2021-44230
Published on: Not Yet Published
Last Modified on: 12/01/2021 08:36:00 PM UTC
Certain versions of Windows from Microsoft contain the following vulnerability:
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.
- CVE-2021-44230 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Enterprise Edition 2021.11 | Releases | portswigger.net text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows | - | All | All | All |
Application | Portswigger | Burp Suite | All | All | All | All |
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:a:portswigger:burp_suite:*:*:*:*:enterprise:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-44230 : PortSwigger Burp Suite Enterprise Edition before 2021.11 on #Windows has weak file permissions for… twitter.com/i/web/status/1… | 2021-11-30 19:09:49 |
![]() |
Potentially Critical CVE Detected! CVE-2021-44230 Description: PortSwigger Burp Suite Enterprise Edition before 202… twitter.com/i/web/status/1… | 2021-11-30 20:00:36 |
![]() |
CVE-2021-44230 عارفين في ايه في Burp Suite Enterprise Edition before 2021.11 ?? بيرب هيغنى دلوقتى اللى منى مه… twitter.com/i/web/status/1… | 2021-11-30 20:00:53 |