We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Assigner | DIVD |
Reserved | 2022-02-14 |
Published | 2022-06-08 |
Updated | 2024-09-17 |
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.
Wietse Boonstra of DIVD
Hidde Smit of DIVD
https://csirt.divd.nl/DIVD-2021-00037
https://csirt.divd.nl/CVE-2022-25153
Support options