Описание
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 25.4.270 (исключая)
cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-424
Связанные уязвимости
CVSS3: 6.7
github
6 месяцев назад
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.
EPSS
Процентиль: 3%
0.00016
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-424