PT-2023-4945 · Ibm · Ibm Qradar Wincollect Agent
Alexander Staalgaard
·
Published
2023-07-25
·
Updated
2023-09-13
·
CVE-2023-38736
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM QRadar WinCollect Agent versions 10.0 through 10.1.6
Description
The issue is related to insufficient access control in the IBM QRadar WinCollect Agent, which can be exploited by a remote attacker to elevate their privileges. A normal user could utilize this vulnerability to gain SYSTEM permissions when the agent is installed to run as ADMIN or SYSTEM.
Recommendations
For IBM QRadar WinCollect Agent versions 10.0 through 10.1.6, consider restricting the agent's privileges to prevent a local escalation of privilege attack until a patch is available. As a temporary workaround, avoid running the agent as ADMIN or SYSTEM to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Qradar Wincollect Agent