Описание
Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.exe SYSTEM process with PROCESS_ALL_ACCESS rights.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 12.1.4.27 (исключая)
cpe:2.3:a:aternity:aternity:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00067
Низкий
7.8 High
CVSS3
Дефекты
NVD-CWE-Other
CWE-269
Связанные уязвимости
CVSS3: 7.8
github
около 3 лет назад
Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.exe SYSTEM process with PROCESS_ALL_ACCESS rights.
EPSS
Процентиль: 21%
0.00067
Низкий
7.8 High
CVSS3
Дефекты
NVD-CWE-Other
CWE-269