PT-2023-15388 · Rsa · Rsa Netwitness Platform

Hyp3Rlinx

·

Publicado

2023-03-24

·

Atualizado

2024-04-11

·

CVE-2022-47529

CVSS v3.1

6.7

Média

VetorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RSA NetWitness Platform versions prior to 12.2
Description The issue allows local and admin Windows user accounts to modify the endpoint agent service configuration, either disabling it completely or running user-supplied code or commands. This bypasses tamper-protection features via ACL modification.
Recommendations For versions prior to 12.2, update to version 12.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the endpoint agent service configuration to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2022-47529

Produtos afetados

Rsa Netwitness Platform