CVE-2023-26441
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Aug 2, 2023
Updated: Jan 12, 2024
CWE ID 22
CWE ID 200
Summary
CVE-2023-26441 is a vulnerability affecting Cacheservice where it fails to properly check the absolute location of cache objects, leading to potential Arbitrary File Read access for attackers with database access and network privileges. The vulnerability could allow the attacker to read local file system resources that are accessible to the services system user account. This issue has been mitigated through improved path validation, ensuring that all access is confined to the defined root directory, and no publicly available exploits have been reported.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share