CVE-2023-47267
Last modified
CVE-2023-47267 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thegreenbow | Thegreenbow Vpn Client | >= 6.52.004, < 6.52.006 |
| Thegreenbow | Thegreenbow Vpn Client | >= 6.87.001, < 6.87.108 |
| Thegreenbow | Thegreenbow Vpn Client | >= 6.87.001, < 6.87.109 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-47267?
How severe is CVE-2023-47267?
How do I fix CVE-2023-47267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-47260Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via …6.1
- CVE-2023-47261Dokmee ECM 7.4.6 allows remote code execution because the re…9.8
- CVE-2023-47262The startup process and device configurations of the Abbott …5.2
- CVE-2023-47263Certain WithSecure products allow a Denial of Service (DoS) …7.5
- CVE-2023-47264Certain WithSecure products have a buffer over-read whereby …7.5
- CVE-2023-47265Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XS…5.4
- CVE-2023-47268In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer th…5.3
- CVE-2023-4727A flaw was found in dogtag-pki and pki-core. The token authe…7.5
- CVE-2023-47271PKP-WAL (aka PKP Web Application Library or pkp-lib) before …5.3
- CVE-2023-47272Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows X…6.1
- CVE-2023-47279In Delta Electronics InfraSuite Device Master v.1.0.7, A vul…7.5
- CVE-2023-4728The LadiApp plugin for WordPress is vulnerable to unauthoriz…5.4
Are you affected by CVE-2023-47267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
