An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-10-25T13:07:01.819Z
Reserved: 2023-06-28T07:03:39.592Z
Link: CVE-2023-3438

Updated: 2024-08-02T06:55:03.399Z

Status : Modified
Published: 2023-07-03T08:15:09.670
Modified: 2024-11-21T08:17:16.007
Link: CVE-2023-3438

No data.