A Race Condition exists in the Qualys Cloud Agent for Windows
platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to
escalate privileges limited on the local machine during uninstallation of the
Qualys Cloud Agent for Windows. Attackers may gain SYSTEM level privileges on
that asset to run arbitrary commands.
At the time of this disclosure, versions before 4.0 are classified as End
of Life.
References
Link | Resource |
---|---|
https://www.qualys.com/security-advisories/ | Vendor Advisory |
https://www.qualys.com/security-advisories/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:54
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
References | () https://www.qualys.com/security-advisories/ - Vendor Advisory |
Information
Published : 2023-04-18 16:15
Updated : 2024-11-21 07:54
NVD link : CVE-2023-28142
Mitre link : CVE-2023-28142
CVE.ORG link : CVE-2023-28142
JSON object : View
Products Affected
qualys
- cloud_agent
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')