NA

CVE-2024-27460

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

Vulnerability Trend

Exploits

Plantronics Hub version 3251 suffers from an arbitrary file read vulnerability ...

Github Repositories

HP Plantronics Hub 3.2.1 Updater Privilege Escalation

CVE-2024-27460 HP Plantronics Hub 321 Updater Privilege Escalation/Arbitrary File Read Description: Affected versions HP Plantronics Hub 321 Impacted service(s) Insecure Path: "C:\ProgramData\Plantronics\Spokes3G" Service: PlantronicsUpdateService Steps to reproduce (POC): Open cmdexe Navigate using cd C:\ProgramData\Plantronics\Spokes3G echo ^|^|<FULL-PA

Plantronics Desktop Hub LPE

CVE-2024-27460 - Plantronics Desktop Hub LPE Arbitrary File Delete to SYSTEM Majority of code is based on the referenced PoC by @filip_dragovic Thanks @filip_dragovic & @k0zmer :) Blog Post: mantodeasecurityde/en/2024/05/cve-2024-27460-plantronics-hub-lpe References supporthpcom/us-en/document/ish_9869257-9869285-16/hpsbpy03895 githubcom/W