CVE-2023-6335

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
References
Link Resource
https://www.hypr.com/security-advisories Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hypr:workforce_access:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Jan 2024, 16:25

Type Values Removed Values Added
First Time Hypr workforce Access
Microsoft windows
Hypr
Microsoft
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 7.8
References () https://www.hypr.com/security-advisories - () https://www.hypr.com/security-advisories - Vendor Advisory
CPE cpe:2.3:a:hypr:workforce_access:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Summary
  • (es) La vulnerabilidad de resolución de enlace incorrecta antes del acceso al archivo ("Link Following") en HYPR Workforce Access en Windows permite el nombre de archivo controlado por el usuario. Este problema afecta a Workforce Access: antes de 8.7.

16 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 20:15

Updated : 2024-01-23 16:25


NVD link : CVE-2023-6335

Mitre link : CVE-2023-6335

CVE.ORG link : CVE-2023-6335


JSON object : View

Products Affected

microsoft

  • windows

hypr

  • workforce_access
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')