Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrpm-72v9-33v3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

EPSS

Процентиль: 93%
0.11082
Средний

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

EPSS

Процентиль: 93%
0.11082
Средний

Дефекты

CWE-502