PT-2021-17742 · Forescout · Forescout Counteract

Published

2021-04-14

·

Updated

2021-04-21

·

CVE-2021-28098

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Forescout CounterACT versions prior to 8.1.4
Description: A local privilege escalation issue is present in the logging function of the affected software. The SecureConnector component runs with administrative privileges and writes log entries to a file with full permissions for the Everyone group. An attacker can exploit this by creating a symbolic link to point the log file to a privileged location, such as %WINDIR%System32, allowing for DLL hijacking.
Recommendations: For versions prior to 8.1.4, update to version 8.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the logging function or the %PROGRAMDATA%ForeScout SecureConnector directory to minimize the risk of exploitation.

Exploit

Fix

Link Following

Incorrect Permission

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28098

Affected Products

Forescout Counteract