What the vulnerability does

01Description

Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files and lead to local privilege escalation.

Key dates

02Disclosure timeline

April 23, 2021 CVE published
August 3, 2024 Record updated