Iniciar sesión

¿No tiene una cuenta? Cree una.

System Recovery Hotfix 860045

Parche

Resumen

Restricting security permissions for low privilege users

Descripción

The System Recovery folder is vulnerable to attackers as low privileged users. See CVE-2023-28047 for more details.

 

Remediation

This script needs to be applied to restrict the “create” or “write” permissions to the System Recovery Install path folder for a low privilege user

·       If Hotfix is already applied for the previous versions, we need not re-apply post upgrade

·       For fresh install scenarios, this needs to be applied

The existing System Recovery customers who are running in low privilege user mode must execute the script available below. This script applies to all versions of System Recovery.

 

Applies

To all supported System Recovery versions

 

Mitigation

A new PowerShell script has been created which provides Read/Execute permissions and denies all other permissions for low privilege users. The downloadable file SR_HF_860045.zip contains the script FolderPermission.ps1. A PDF with execution instructions can be downloaded below or accessed in Article 100065391. The PDF instructions contain an older file name. The file SR_HF_860045 is the correct file to run. 

 

Se aplica a las siguientes versiones del producto

Actualizar archivos

Nombre del archivo Descripción Versión Plataforma Tamaño