📦

take_control

Vendor: rahul_singla

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 0.72% Exploit Prob.
Latest CVE CVE-2023-27470 Sep 11

Security Vulnerability Index

Page 1 / 1
7.0 CVSS
CVE-2023-27470
Exploit Found

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

EPSS: 0.54%
6.8 CVSS

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

EPSS: 0.89%