VulnerabilityModified
CVE-2005-2382
Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality.
HIGH 7.2EPSS 0.51%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Affected
- oray/peanuthull
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112190569628213&w=2
- http://secunia.com/advisories/16124
- http://secway.org/advisory/AD20050720EN.txtExploit, Vendor Advisory
- http://www.securityfocus.com/bid/14330
- http://marc.info/?l=bugtraq&m=112190569628213&w=2
- http://secunia.com/advisories/16124
- http://secway.org/advisory/AD20050720EN.txtExploit, Vendor Advisory
- http://www.securityfocus.com/bid/14330
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.