Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27470


BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.


Published

2023-09-11T15:15:52.727

Last Modified

2024-11-21T07:52:58.177

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application n-able take_control < 7.0.43 Yes
Operating System microsoft windows - No

References