CVE-2023-38402 is a local privilege escalation vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client for Windows, allowing authenticated users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a low attack complexity and requiring local user privileges, with a high impact on integrity and availability, potentially leading to a Denial-of-Service condition affecting the Windows boot process. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0CPE matchmatch criteria | cpe:2.3:a:hp:aruba_virtual_intranet_access:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.