We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-25153

ITarian - Local privilege escalation in Endpoint Manager agent on Windows



AssignerDIVD
Reserved2022-02-14
Published2022-06-08
Updated2024-09-17

Description

The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.



HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

any version before 6.43.41148.21120
affected

Credits

Wietse Boonstra of DIVD finder

Hidde Smit of DIVD finder

References

https://csirt.divd.nl/DIVD-2021-00037 third-party-advisory

https://csirt.divd.nl/CVE-2022-25153 third-party-advisory

cve.org CVE-2022-25153

nvd.nist.gov CVE-2022-25153

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-25153

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.