PT-2021-17742 · Forescout · Forescout Counteract
Published
2021-04-14
·
Updated
2021-04-21
·
CVE-2021-28098
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Forescout CounterACT versions prior to 8.1.4
Description:
A local privilege escalation issue is present in the logging function of the affected software. The SecureConnector component runs with administrative privileges and writes log entries to a file with full permissions for the Everyone group. An attacker can exploit this by creating a symbolic link to point the log file to a privileged location, such as %WINDIR%System32, allowing for DLL hijacking.
Recommendations:
For versions prior to 8.1.4, update to version 8.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the logging function or the %PROGRAMDATA%ForeScout SecureConnector directory to minimize the risk of exploitation.
Exploit
Fix
Link Following
Incorrect Permission
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forescout Counteract