Lucene search

K
cveMitreCVE-2022-47529
HistoryMar 28, 2023 - 1:15 p.m.

CVE-2022-47529

2023-03-2813:15:07
mitre
web.nvd.nist.gov
68
cve-2022-47529
insecure win32
memory objects
endpoint windows agents
rsa netwitness platform
tamper-protection
acl modification

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

20.5%

Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.

Affected configurations

Nvd
Node
rsanetwitnessRange<12.2
VendorProductVersionCPE
rsanetwitness*cpe:2.3:a:rsa:netwitness:*:*:*:*:*:*:*:*

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

20.5%