PT-2022-9915 · Hewlett Packard · Hpe Agentless Management Service For Windows

Published

2022-02-04

·

Updated

2022-02-09

·

CVE-2021-29218

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Agentless Management Service for Windows versions prior to 1.44.0.0 HPE Agentless Management Service for Windows version 10.96.0.0
Description A local unquoted search path security issue has been identified. This could be exploited locally by a user with high privileges to execute malware, potentially leading to a loss of confidentiality, integrity, and availability.
Recommendations For HPE Agentless Management Service for Windows versions prior to 1.44.0.0, update to version 1.44.0.0 or later to resolve the vulnerability. For HPE Agentless Management Service for Windows version 10.96.0.0, update to a version that includes the fix for this issue, as provided by HPE.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29218

Affected Products

Hpe Agentless Management Service For Windows