PT-2021-20655 · Appdynamics · Appdynamics .Net Agent For Windows

Published

2021-08-18

·

Updated

2021-08-26

·

CVE-2021-34745

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AppDynamics .NET Agent for Windows versions prior to 21.7
Description: A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM privileges. This issue is due to the .NET Agent Coordinator Service executing code with SYSTEM privileges. An attacker with local access to a device running the vulnerable agent could create a custom process that would be launched with those SYSTEM privileges. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.
Recommendations: For versions prior to 21.7, update to AppDynamics .NET Agent Release 21.7 to resolve the issue. As a temporary workaround, consider restricting access to the .NET Agent Coordinator Service to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34745

Affected Products

Appdynamics .Net Agent For Windows