1E Client installer can perform arbitrary file deletion...
High severity
Unreviewed
Published
Oct 5, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Oct 5, 2023
Published to the GitHub Advisory Database
Oct 5, 2023
Last updated
Apr 4, 2024
1E Client installer can perform arbitrary file deletion on protected files.
A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available Q23092 that forces the 1E Client to check for a symbolic link or junction and if it finds one refuses to use that path and instead creates a path involving a random GUID.
References