QID 379330
Date Published: 2024-03-20
QID 379330: Shibboleth Service Provider (SP) Privilege Escalation Vulnerability (CVE-2023-22947)
Shibboleth is a single sign-on log-in system for computer networks and the Internet.
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder.
Affected Versions:
All versions prior to 3.4.1
QID Detection Logic(authenticated):
This QID checks to see if the target is running a vulnerable version of Shibboleth Service Provider.
Successful exploitation of the vulnerability allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder.
Solution
Customers are advised to update to the latest version refer CVE-2023-22947 advisory for latest updates.
Vendor References
CVEs related to QID 379330
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Shibboleth Service Provider |
|