PT-2020-18675 · Webroot · Webroot Endpoint Agent

Published

2020-06-15

·

Updated

2020-06-22

·

CVE-2020-5754

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Webroot endpoint agents versions prior to 9.0.28.48
Description The issue allows remote attackers to trigger a type confusion vulnerability over the listening TCP port of Webroot endpoint agents, resulting in crashing or reading memory contents of the agent.
Recommendations For versions prior to 9.0.28.48, update to version 9.0.28.48 or later to resolve the issue. As a temporary workaround, consider restricting access to the TCP port used by the Webroot endpoint agent to minimize the risk of exploitation.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5754

Affected Products

Webroot Endpoint Agent