PT-2018-13699 · Absolute · Ctes Windows Agent
Publicado
2018-09-08
·
Atualizado
2019-10-03
·
CVE-2018-16715
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Absolute Software CTES Windows Agent versions through 1.0.0.1479
Description
An issue was discovered that allows low-privileged user accounts to have write access to the %ProgramData%CTES folder and sub-folders. This enables unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, resulting in elevated (SYSTEM) user access. Additionally, configuration control files or data files under this folder could be modified to affect service process behavior.
Recommendations
For Absolute Software CTES Windows Agent versions through 1.0.0.1479, consider restricting write access to the %ProgramData%CTES folder and sub-folders to prevent unauthorized modifications. As a temporary workaround, monitor the folder and its contents for any suspicious changes until a fix is available.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ctes Windows Agent