File Permissions Bypass in CyberArk Endpoint Privilege Manager
CVE-2018-14894

7.8HIGH

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
9 April 2019

What is CVE-2018-14894?

CyberArk Endpoint Privilege Manager versions 10.2.1.603 and earlier have a vulnerability that allows an attacker with permissions to edit a file to bypass security mechanisms and execute previously blocked applications. This weakness may lead to unauthorized access and execution of sensitive applications, highlighting the need for immediate attention from system administrators to ensure endpoints remain secure.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.