PT-2019-9562 · Capmon · Capmon Access Manager

Publicado

2019-03-15

·

Atualizado

2019-03-18

·

CVE-2018-18253

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CapMon Access Manager version 5.4.1.1005
Description An issue in CapMon Access Manager allows an unprivileged user to be added to the local Administrators group for a short time to execute a command. However, if the command crashes, the user remains in the Administrators group. Additionally, there is a race condition that occurs in all cases.
Recommendations For CapMon Access Manager version 5.4.1.1005, consider implementing access controls to prevent unprivileged users from being added to the local Administrators group, and ensure that the user is removed from the group after command execution, even if the command crashes. As a temporary workaround, restrict access to the CALRunElevated.exe executable to minimize the risk of exploitation.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18253

Produtos afetados

Capmon Access Manager