CVE-2023-22947

HIGH

Shibboleth Service Provider < 3.4.1 - Uncontrolled Search Path

Title source: rule

Description

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

shibboleth/service_provider < 3.4.1

Timeline

Published Jan 11, 2023
Tracked Since Feb 18, 2026