CVE-2023-22947
HIGHShibboleth Service Provider < 3.4.1 - Uncontrolled Search Path
Title source: ruleDescription
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
10.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
shibboleth/service_provider
< 3.4.1
Timeline
Published
Jan 11, 2023
Tracked Since
Feb 18, 2026