漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objects
Vulnerability Description
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various plugin scripts and executables on the endpoint in order to gather and report information about the host to the CounterACT management appliance. The SecureConnector agent downloads these scripts and executables as needed from the CounterACT management appliance and runs them on the endpoint. The SecureConnector agent fails to set any permissions on downloaded file objects. This allows a malicious user to take ownership of any of these files and make modifications to it, regardless of where the files are saved. These files are then executed under SYSTEM privileges. A malicious unprivileged user can overwrite these executable files with malicious code before the SecureConnector agent executes them, causing the malicious code to be run under the SYSTEM account.
CVSS Information
N/A
Vulnerability Type
创建拥有不安全权限的临时文件
Vulnerability Title
ForeScout CounterACT 权限许可和访问控制漏洞
Vulnerability Description
ForeScout CounterACT是一款网络准入控制产品。 ForeScout CounterACT中存在权限许可和访问控制漏洞,该漏洞源于程序以不安全的方式创建文件。本地攻击者可借助恶意的代码利用该漏洞覆盖可执行文件并执行该恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A