logo

CVE-2023-6080: A Case Study on Third-Party Installer Abuse

ID: 920e31b3-64fb-59d0-aefb-101d91639a57

STIX ID: report--920e31b3-64fb-59d0-aefb-101d91639a57

Feed Name: Google Cloud Threat Intelligence

Threat Score
55/100

Date Published: 2025-02-03

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant details CVE-2023-6080: a privilege escalation vulnerability in Lakeside SysTrack's MSI installer where misconfigured Custom Actions and use of the user's %TEMP% directory (plus predictable filename fallback) allow a low-privilege user to exploit race conditions to execute as NT AUTHORITY\SYSTEM. The report offers defensive guidance (use protected folders, strengthen filename randomness, audit endpoints, monitor elevated shells) and notes the flaw was reported in June 2024 and fixed in version 11.0 by August 7, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.