CVE-2023-28141 is an NTFS Junction condition vulnerability in the Qualys Cloud Agent for Windows, affecting versions prior to 4.8.0.31. This local vulnerability has a CVSS score of 6.3 (Medium) and allows an attacker with low privileges to write files to arbitrary locations during installation/uninstallation, potentially leading to unauthorized modification or deletion of sensitive files. There is no known public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.3.34, < 4.8.0.31CPE matchmatch criteria | cpe:2.3:a:qualys:cloud_agent:*:*:*:*:*:windows:*:* | ||
>= 3.1.3.34, < 4.8.0.31CPE match | cpe:2.3:a:qualys:cloud_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023Possible NTFS Junction Exploitation on Qualys Cloud Agent for Windows prior to 4.8.0.31 [CVE-2023-28141]
Apr 18, 2023