VendorsPaninieverest_engine2.0.4
Vulnerabilities

Panini Everest Engine 2.0.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2022-39959
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe and therefore a Trojan horse %PROGRAMDATA%\Panini\Everest.exe may be executed instead of the intended vendor-supplied EverestEngine.exe file.
Published 2022-10-07 · Modified
7.8EPSS 0.006