PT-2021-14879 · Proofpoint · Proofpoint Insider Threat Management Agent For Windows

Denis Faiustov

+1

·

Published

2021-01-26

·

Updated

2021-02-04

·

CVE-2021-22159

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Proofpoint Insider Threat Management Agent for Windows versions prior to 7.4.3 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.5.4 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.6.5 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.7.5 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.8.4 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.9.3 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.10.2 Proofpoint Insider Threat Management Agent for Windows versions prior to 7.11.0.25 Proofpoint Insider Threat Management Agent for Windows version 7.3 and earlier
Description: The Proofpoint Insider Threat Management Agent for Windows is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. Agents for MacOS, Linux, and ITM Cloud are not affected.
Recommendations: For versions prior to 7.4.3, update to version 7.4.3 or later. For versions prior to 7.5.4, update to version 7.5.4 or later. For versions prior to 7.6.5, update to version 7.6.5 or later. For versions prior to 7.7.5, update to version 7.7.5 or later. For versions prior to 7.8.4, update to version 7.8.4 or later. For versions prior to 7.9.3, update to version 7.9.3 or later. For versions prior to 7.10.2, update to version 7.10.2 or later. For versions prior to 7.11.0.25, update to version 7.11.0.25 or later. For version 7.3 and earlier, update to a version later than 7.3.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22159

Affected Products

Proofpoint Insider Threat Management Agent For Windows