PT-2024-26066 · Unknown · Dualdarmanagerproxy

Balance

·

Published

2024-09-03

·

Updated

2024-09-05

·

CVE-2024-34647

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DualDarManagerProxy versions prior to SMR Sep-2024 Release 1
Description The issue is related to the incorrect use of a privileged API in DualDarManagerProxy, allowing local attackers to access privileged APIs related to Knox without a proper license. This flaw enables local privilege escalation via the Knox API.
Recommendations For versions prior to SMR Sep-2024 Release 1, update to the SMR Sep-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the privileged APIs related to Knox until a patch is available.

Fix

Related Identifiers

CVE-2024-34647

Affected Products

Dualdarmanagerproxy