PT-2021-20655 · Appdynamics · Appdynamics .Net Agent For Windows
Published
2021-08-18
·
Updated
2021-08-26
·
CVE-2021-34745
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
AppDynamics .NET Agent for Windows versions prior to 21.7
Description:
A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM privileges. This issue is due to the .NET Agent Coordinator Service executing code with SYSTEM privileges. An attacker with local access to a device running the vulnerable agent could create a custom process that would be launched with those SYSTEM privileges. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.
Recommendations:
For versions prior to 21.7, update to AppDynamics .NET Agent Release 21.7 to resolve the issue. As a temporary workaround, consider restricting access to the .NET Agent Coordinator Service to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appdynamics .Net Agent For Windows