PT-2023-22278 · Microsoft+1 · Windows+1
Published
2023-12-20
·
Updated
2024-09-25
·
CVE-2023-29486
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Heimdal Thor agent versions 3.4.2 through 3.7.0
Description
An issue in the Heimdal Thor agent allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via the Next-Gen Antivirus component. Heimdal argues that this limitation is a Microsoft Windows issue, not a Heimdal-specific vulnerability, as their USB control solution is meant to manage Microsoft Windows native USB restrictions.
Recommendations
For Heimdal Thor agent versions 3.4.2 through 3.7.0, consider disabling the Next-Gen Antivirus component as a temporary workaround to minimize the risk of exploitation. Restrict access to USB devices to prevent bypassing of USB access restrictions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heimdal Thor Agent
Windows