Cloud Foundry Foundation bosh-windows-stemcell-builder
- < v2019.98
A vulnerability exists in BOSH-Ecosystem BOSH Windows Stemcell Builder, specifically in the BOSH.Utils.psm1 file, prior to version 2019.98. This vulnerability allows low-privilege authenticated users to overwrite service_wrapper.exe or bosh-agent.exe. Exploiting this issue can lead to gaining NT AUTHORITY\SYSTEM privileges upon the next service restart or reboot, potentially allowing full control over the host.
Exploitation of this vulnerability could result in unauthorized users gaining NT AUTHORITY\SYSTEM privileges, allowing them to execute arbitrary commands with system-level rights and control the host machine.
Users are advised to upgrade to BOSH Windows Stemcell Builder version 2019.98 or greater.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.