Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
2019-04-17T15:29:00.377
2024-11-21T03:42:24.030
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | beyondtrust | avecto_defendpoint | < 4.4.267.0 | Yes |
Application | beyondtrust | avecto_defendpoint | < 5.1.149.0 | Yes |