Vulnerability identifier: #VU15808
Vulnerability risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-264
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Atlassian Crucible
Client/Desktop applications /
Office applications
Atlassian Fisheye
Client/Desktop applications /
Office applications
Vendor:
Atlassian
Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists in Microsoft Windows Installer due to weak permissions on the installation directory. A local attacker can gain elevated privileges.
Mitigation
Update the affected software to versions 4.6.1, 4.7.0.
Vulnerable software versions
Atlassian Crucible: 4.0.0 - 4.6.0
Atlassian Fisheye: 4.0.0 - 4.6.0
External links
https://jira.atlassian.com/browse/CRUC-8314
https://jira.atlassian.com/browse/FE-7105
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.