In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.
2018-06-11T20:29:00.300
2024-11-21T04:10:48.497
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet | < 1.10.13 | Yes |
Application | puppet | puppet | < 5.3.7 | Yes |
Application | puppet | puppet | < 5.5.2 | Yes |
Operating System | microsoft | windows | - | No |