Permissions, Privileges, and Access Controls in YubiKey Manager - #VU88198
Published: April 8, 2024 / Updated: April 9, 2024
YubiKey Manager
Yubico
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. If a user runs the YubiKey Manager GUI as Administrator, browser windows opened by YubiKey Manager GUI may be opened as Administrator which could be exploited by a local attacker to perform actions as Administrator.