Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
2018-06-11T20:29:00.360
2024-11-21T04:10:48.610
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | puppet | puppet | < 1.10.13 | Yes |
| Application | puppet | puppet | < 5.3.7 | Yes |
| Application | puppet | puppet | < 5.5.2 | Yes |
| Operating System | microsoft | windows | - | No |