PT-2021-12816 · Proofpoint · Proofpoint Insider Threat Management Agent For Windows

Lee Christensen

·

Published

2021-01-06

·

Updated

2021-01-13

·

CVE-2020-8884

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Proofpoint Insider Threat Management Windows Agent versions prior to 7.9
Description: The issue allows remote authenticated users to execute arbitrary code as SYSTEM due to improper deserialization over named pipes in the rcdsvc component of the Proofpoint Insider Threat Management Windows Agent.
Recommendations: For versions prior to 7.9, update to version 7.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the named pipes used by the rcdsvc component to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8884

Affected Products

Proofpoint Insider Threat Management Agent For Windows