Description
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29896 | The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup. |
References
History
No history.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-03-11T13:39:17.610Z
Reserved: 2022-02-14T00:00:00.000Z
Link: CVE-2022-25153
No data.
Status : Modified
Published: 2022-06-09T17:15:08.903
Modified: 2024-11-21T06:51:42.310
Link: CVE-2022-25153
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD