Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWebroot Endpoint Agents
APPWebroot< 9.0.28.48
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
Related vulnerabilities
CVE-2020-5754CRITICAL9.1PL ✓same product
Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash
CVE-2024-7826CRITICAL9.8PL ✓same vendor
Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności
CVE-2024-7825CRITICAL9.8PL ✓same vendor
Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji
CVE-2024-7824CRITICAL9.8PL ✓same vendor
Type Confusion w Webroot SecureAnywhere Web Shield umożliwia nadużycie funkcjonalności
CVE-2018-4012CRITICAL9.0PL ✓same vendor
Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP