PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://gitlab.com/-/snippets/2017709 | third party advisory exploit |
https://docs.pingidentity.com/bundle/pingid/page/xqz1597139945488.html | release notes vendor advisory |