Vulnerabilities > CVE-2022-24618 - Improper Preservation of Permissions vulnerability in Heimdalsecurity Heimdal Premium Security 2.5.383/2.5.385/2.5.395

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
heimdalsecurity
CWE-281

Summary

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.

Common Weakness Enumeration (CWE)