CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-36495: Read/Write Permissions for Everyone on Configuration File

Description

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:

C:\ProgramData\WINSelect\WINSelect.wsd

The path for the affected WINSelect Enterprise configuration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

Classification

CVE ID: CVE-2024-36495

Affected Products

Vendor: Faronics

Product: WINSelect (Standard + Enterprise)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.39% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://r.sec-consult.com/winselect
https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes
http://seclists.org/fulldisclosure/2024/Jun/12

Timeline