We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-25153

ITarian - Local privilege escalation in Endpoint Manager agent on Windows



Description

The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.

Reserved 2022-02-14 | Published 2022-06-08 | Updated 2025-03-11 | Assigner DIVD


HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-275 Permission Issues

Product status

any version before 6.43.41148.21120
affected

Credits

Wietse Boonstra (DIVD) finder

Hidde Smit (DIVD) finder

Frank Breedijk (DIVD) analyst

Victor Pasman (DIVD) analyst

Vicotr Gevers (DIVD) analyst

References

csirt.divd.nl/DIVD-2021-00037 third-party-advisory

csirt.divd.nl/CVE-2022-25153 third-party-advisory

cve.org (CVE-2022-25153)

nvd.nist.gov (CVE-2022-25153)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-25153

Support options

Helpdesk Chat, Email, Knowledgebase
MonTueWedThuFriSatSun
242526272812345678910111213141516171819202122232425262728293031123456
MonTueWedThuFriSatSun
242526272812345678910111213141516171819202122232425262728293031123456