PT-2021-13516 · Duo · Duo Authentication Proxy

Published

2021-03-25

·

Updated

2021-03-27

·

CVE-2021-1492

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Duo Authentication Proxy versions prior to 5.2.1
Description: The issue arises from the Duo Authentication Proxy installer not properly validating file installation paths, allowing an attacker with local user privileges to write to arbitrary privileged directories. This can lead to manipulation of files used by the installer, Denial of Service (DoS) by deleting files, or replacement of system files to potentially achieve elevation of privileges. The exploitation is limited to the time when the installer is running during new installations and is not possible after the installation has finished.
Recommendations: For versions prior to 5.2.1, update to version 5.2.1 to address the issue. As a temporary workaround, consider restricting the privileges of the installer to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-1492

Affected Products

Duo Authentication Proxy