PT-2018-13699 · Absolute · Ctes Windows Agent
Published
2018-09-08
·
Updated
2019-10-03
·
CVE-2018-16715
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Absolute Software CTES Windows Agent versions through 1.0.0.1479
Description
An issue was discovered that allows low-privileged user accounts to have write access to the %ProgramData%CTES folder and sub-folders. This enables unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, resulting in elevated (SYSTEM) user access. Additionally, configuration control files or data files under this folder could be modified to affect service process behavior.
Recommendations
For Absolute Software CTES Windows Agent versions through 1.0.0.1479, consider restricting write access to the %ProgramData%CTES folder and sub-folders to prevent unauthorized modifications. As a temporary workaround, monitor the folder and its contents for any suspicious changes until a fix is available.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ctes Windows Agent