PT-2019-9562 · Capmon · Capmon Access Manager

Published

2019-03-15

·

Updated

2019-03-18

·

CVE-2018-18253

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CapMon Access Manager version 5.4.1.1005
Description An issue in CapMon Access Manager allows an unprivileged user to be added to the local Administrators group for a short time to execute a command. However, if the command crashes, the user remains in the Administrators group. Additionally, there is a race condition that occurs in all cases.
Recommendations For CapMon Access Manager version 5.4.1.1005, consider implementing access controls to prevent unprivileged users from being added to the local Administrators group, and ensure that the user is removed from the group after command execution, even if the command crashes. As a temporary workaround, restrict access to the CALRunElevated.exe executable to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18253

Affected Products

Capmon Access Manager