An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection capabilities.
The vulnerability results from insufficient effectiveness of the USB device control mechanism implemented in the Next-Gen Antivirus component of the Heimdal Thor agent. An attacker can bypass imposed USB access restrictions, which opens the possibility of executing malicious code from a connected drive. It is worth noting that the manufacturer itself — Heimdal — disputes the attribution of this vulnerability solely to their product, arguing that the solution works as a management layer over native Windows mechanisms and the limitations lie with Microsoft's operating system.
An attacker can execute arbitrary code on the vulnerable system (RCE) and gain access to sensitive information, as well as bypass USB device access control policies.
Update Heimdal Thor agent to version 3.7.0 or later. It is also recommended to review USB control policies at the Windows operating system level and implement additional access control mechanisms for peripheral devices independently of the Heimdal solution.
Heimdal Thor agent in versions 3.4.2 and earlier (before version 3.7.0) running on Microsoft Windows platform.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple macOS
OSAppleall versionsHeimdalsecurity Thor
APPHeimdalsecurity< 3.7.0≤ 2.6.9Microsoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP