CVE-2023-35863

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
05/07/2023
Last modified:
14/07/2023

Description

In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:madefornet:http_debugger:*:*:*:*:*:*:*:* 9.12 (including)