Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWebroot Endpoint Agents
APPWebroot< 9.0.28.48
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
LPE
CWE
Powiązane podatności
CVE-2020-5754CRITICAL9.1PL ✓ten sam produkt
Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash
CVE-2024-7826CRITICAL9.8PL ✓ten sam vendor
Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności
CVE-2024-7825CRITICAL9.8PL ✓ten sam vendor
Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji
CVE-2024-7824CRITICAL9.8PL ✓ten sam vendor
Type Confusion w Webroot SecureAnywhere Web Shield umożliwia nadużycie funkcjonalności
CVE-2018-4012CRITICAL9.0PL ✓ten sam vendor
Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP