216.73.216.6

CVE-2024-11948

· Published 12/12/2024 01:40 · Modified 13/12/2024 19:32

Labels: CVE-2024-11948 2024-12-12CVE-2024-11948NVD-CWE-noinfo[email protected]

Essential information

Published
12/12/2024 01:40
Modified
13/12/2024 19:32
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gfi / archiver cpe:2.3:a:gfi:archiver:*:*:*:*:*:*:*:*

References