CVE-2022-23909 describes an unquoted service path vulnerability in Sherpa Connector Service (SherpaConnectorService.exe) versions 2020.2.20328.2050, affecting Gimmal and Microsoft Windows environments. This flaw allows a local attacker to achieve privilege escalation by placing a malicious executable in a specific path, due to the service's improper handling of its executable path. Rated with a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and can lead to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or actively exploited, exploit code is publicly available on ExploitDB, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2020.2.20328.2050CPE matchmatch criteria | cpe:2.3:a:gimmal:sherpa_connector_service:2020.2.20328.2050:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.