We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.
Reserved 2022-02-14 | Published 2022-06-08 | Updated 2025-03-11 | Assigner DIVDWietse Boonstra (DIVD)
Hidde Smit (DIVD)
Frank Breedijk (DIVD)
Victor Pasman (DIVD)
Vicotr Gevers (DIVD)
csirt.divd.nl/DIVD-2021-00037
csirt.divd.nl/CVE-2022-25153
Support options