← Zurück zur CVE-Suche

CVE-2026-47830

BOSH-Ecosystem bosh-windows-stemcell-builder

Beschreibung

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVSS 8.8EPSS 0.1%Risiko 0.89
Quelle öffnen
Veröffentlicht
2026-07-09 07:16:24
Betroffene Versionen
<2019.98
Typ
Firmware
Vektor
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H