Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-36074
HistoryJun 27, 2024 - 12:00 a.m.

CVE-2024-36074

2024-06-2700:00:00
mitre
github.com
7
netwrix cososys
endpoint protector
unify
remote code execution

AI Score

8.1

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. An attacker with administrative access to the Endpoint Protector or Unify server can cause a client to acquire and execute a malicious file resulting in remote code execution.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:netwrix:cososys_endpoint_protector:*:*:*:*:*:*:*:*"
    ],
    "vendor": "netwrix",
    "product": "cososys_endpoint_protector",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "5.9.3"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:netwrix:cososys_unify:*:*:*:*:*:*:*:*"
    ],
    "vendor": "netwrix",
    "product": "cososys_unify",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "7.0.6"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

8.1

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-36074