cve/2023/CVE-2023-27470.md
2024-05-25 21:48:12 +02:00

734 B

CVE-2023-27470

Description

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

POC

Reference

No PoCs from references.

Github