PT-2018-5075 · Forescout · Secureconnector Agent
Ariel Montano Cardenas
+2
·
Publicado
2018-07-13
·
Atualizado
2019-10-09
·
CVE-2016-9485
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SecureConnector agent (affected versions not specified)
Description
The issue concerns the SecureConnector agent's handling of downloaded files. When the agent downloads plugin scripts and executables from the CounterACT management appliance, it fails to set any permissions on these files. This allows a malicious user to take ownership of the files, modify them, and then have them executed under SYSTEM privileges. A malicious unprivileged user can overwrite the executable files with malicious code before the SecureConnector agent executes them, resulting in the malicious code being run under the SYSTEM account.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Secureconnector Agent