PoC
CVE-2023-37250 PoC Write up: atosnet/en/lp/securitydive/roaming-and-racing-to-get-system-cve-2023-37250
Unity Parsec has a TOCTOU race condition that permits local malicious users to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions up to and including 8. Parsec Loader 9 is a fixed version.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
unity parsec |