ZeroHour

CVE-2022-43997

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p30
Published
()
Modified
Description

Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.exe SYSTEM process with PROCESS_ALL_ACCESS rights.

Vendors
aternity
Products
aternity
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.