CVE-2022-25153

The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.
References
Link Resource
https://csirt.divd.nl/CVE-2022-25153 Third Party Advisory
https://csirt.divd.nl/DIVD-2021-00037 Third Party Advisory
https://csirt.divd.nl/CVE-2022-25153 Third Party Advisory
https://csirt.divd.nl/DIVD-2021-00037 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:itarian:endpoint_manager_communication_client:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
References () https://csirt.divd.nl/CVE-2022-25153 - Third Party Advisory () https://csirt.divd.nl/CVE-2022-25153 - Third Party Advisory
References () https://csirt.divd.nl/DIVD-2021-00037 - Third Party Advisory () https://csirt.divd.nl/DIVD-2021-00037 - Third Party Advisory

02 Jan 2024, 19:15

Type Values Removed Values Added
Summary The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup. The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.

07 Nov 2023, 03:44

Type Values Removed Values Added
Summary The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup. The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.

Information

Published : 2022-06-09 17:15

Updated : 2024-11-21 06:51


NVD link : CVE-2022-25153

Mitre link : CVE-2022-25153

CVE.ORG link : CVE-2022-25153


JSON object : View

Products Affected

itarian

  • endpoint_manager_communication_client
CWE
CWE-275

Permission Issues

NVD-CWE-noinfo