CVE-2023-6080: A Case Study on Third-Party Installer Abuse
ID: 920e31b3-64fb-59d0-aefb-101d91639a57
STIX ID: report--920e31b3-64fb-59d0-aefb-101d91639a57
Feed Name: Google Cloud Threat Intelligence
Mandiant details CVE-2023-6080: a privilege escalation vulnerability in Lakeside SysTrack's MSI installer where misconfigured Custom Actions and use of the user's %TEMP% directory (plus predictable filename fallback) allow a low-privilege user to exploit race conditions to execute as NT AUTHORITY\SYSTEM. The report offers defensive guidance (use protected folders, strengthen filename randomness, audit endpoints, monitor elevated shells) and notes the flaw was reported in June 2024 and fixed in version 11.0 by August 7, 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
