Security Permissions Flaw in Absolute Software CTES Windows Agent
CVE-2018-16715

8.8HIGH

Key Information:

Vendor

Absolute

Vendor
CVE Published:
8 September 2018

What is CVE-2018-16715?

A security vulnerability has been identified in Absolute Software CTES Windows Agent prior to version 1.0.0.1479, where insufficient security permissions on the %ProgramData%\CTES directory and its sub-folders could allow low-privileged user accounts to gain write access. This may lead to unauthorized actions, including the replacement of executable (EXE) or dynamically loadable library (DLL) files, potentially granting elevated SYSTEM user access. Additionally, configuration control files or data files within this folder could similarly be tampered with, ultimately affecting the behavior of the service process.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.