vendor:
Unknown
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Read
Unknown
CWE
Product Name: Unknown
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Arbitrary File Read Vulnerability in MsiAdvertiseProduct
The vulnerability exists in the MsiAdvertiseProduct function, where an arbitrary file can be copied to a specific directory, resulting in an arbitrary file read vulnerability. By providing a controlled file as the first parameter, the function can be tricked into copying any file as SYSTEM, making the destination file readable. This can lead to the disclosure of sensitive information.
Mitigation:
No specific mitigation or remediation steps provided.