Avecto Defendpoint 4 prima del 4.4 SR6 e 5 prima di 5.1 SR1 ha una vulnerabilità Percorso di ricerca non attendibile, sfruttabile modificando le variabili di ambiente per innescare elevazione automatica del lancio processo di un utente malintenzionato. |
https://hackandpwn.com/assets/2019-04-17-cve-2018-10959/Defendpoint_Windows_Client_Release_Notes_4.4.267.0_SR6.pdf https://hackandpwn.com/assets/2019-04-17-cve-2018-10959/Defendpoint_Windows_Client_Release_Notes_5.1.149.0_SR1.pdf https://hackandpwn.com/cve-2018-10959/ https://www.beyondtrust.com/docs/release-notes/privilege-management/windows-and-mac/windows/pm-windows-4-4-sr6.pdf https://www.beyondtrust.com/docs/release-notes/privilege-management/windows-and-mac/windows/pm-windows-5-1.pdf https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10959 |
Vulnerabilità: CVE-2018-10959
