PT-2018-13699 · Absolute · Ctes Windows Agent

Published

2018-09-08

·

Updated

2019-10-03

·

CVE-2018-16715

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Absolute Software CTES Windows Agent versions through 1.0.0.1479
Description An issue was discovered that allows low-privileged user accounts to have write access to the %ProgramData%CTES folder and sub-folders. This enables unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, resulting in elevated (SYSTEM) user access. Additionally, configuration control files or data files under this folder could be modified to affect service process behavior.
Recommendations For Absolute Software CTES Windows Agent versions through 1.0.0.1479, consider restricting write access to the %ProgramData%CTES folder and sub-folders to prevent unauthorized modifications. As a temporary workaround, monitor the folder and its contents for any suspicious changes until a fix is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16715

Affected Products

Ctes Windows Agent