PT-2022-18680 · Controlup · Controlup Real-Time Agent

Published

2022-04-27

·

Updated

2022-05-09

·

CVE-2022-27905

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ControlUp Real-Time Agent versions prior to 8.6
Description The issue is related to an unquoted path in the software, which can result in privilege escalation. An attacker would need write permissions to the root level of the OS drive (C:) to exploit this.
Recommendations For versions prior to 8.6, update to version 8.6 or later to resolve the issue. As a temporary workaround, consider restricting write permissions to the root level of the OS drive to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27905

Affected Products

Controlup Real-Time Agent