Microsoft Windows Defender For Endpoint - Path Traversal
Title source: ruleExploitation Summary
EIP tracks 3 public exploits for CVE-2022-29799. PoCs published by joshuavanderpoll, pansyhebephrenic23.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal vulnerability and a symlink TOCTOU race condition in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState property via D-Bus and exploiting a race condition in script execution.
Description
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.
Exploits (3)
This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal vulnerability and a symlink TOCTOU race condition in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState property via D-Bus and exploiting a race condition in script execution.
The repository lacks actual exploit code and instead directs users to download an executable from an external release page. The README is vague, lacks technical details about the vulnerability, and focuses on marketing language.
This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal and symlink TOCTOU vulnerability in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState via D-Bus and exploiting a race condition in script execution.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N