PT-2018-13699 · Absolute · Ctes Windows Agent

Publicado

2018-09-08

·

Atualizado

2019-10-03

·

CVE-2018-16715

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Absolute Software CTES Windows Agent versions through 1.0.0.1479
Description An issue was discovered that allows low-privileged user accounts to have write access to the %ProgramData%CTES folder and sub-folders. This enables unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, resulting in elevated (SYSTEM) user access. Additionally, configuration control files or data files under this folder could be modified to affect service process behavior.
Recommendations For Absolute Software CTES Windows Agent versions through 1.0.0.1479, consider restricting write access to the %ProgramData%CTES folder and sub-folders to prevent unauthorized modifications. As a temporary workaround, monitor the folder and its contents for any suspicious changes until a fix is available.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16715

Produtos afetados

Ctes Windows Agent