CVE-2023-22947

HIGH

Shibboleth Service Provider < 3.4.1 - Unprivileged Local Privilege Escalation via DLL Planting

Title source: llm
STIX 2.1

Description

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

References (2)

Core 2

Scores

CVSS v3 7.3
EPSS 0.0031
EPSS Percentile 22.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
shibboleth/service_provider < 3.4.1
Published Jan 11, 2023
Tracked Since Feb 18, 2026