PT-2024-12106 · Jumpcloud · Jumpcloud Agent

Andrew Oliveau

·

Published

2024-04-26

·

Updated

2024-07-03

·

CVE-2023-26603

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions JumpCloud Agent versions prior to 1.178.0
Description The issue allows privilege escalation to SYSTEM via a repair action in the installer. This is due to the creation of a temporary file in a directory with insecure permissions.
Recommendations For versions prior to 1.178.0, update to version 1.178.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary directory where the file is created to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-26603

Affected Products

Jumpcloud Agent