Security Permissions Flaw in Absolute Software CTES Windows Agent
CVE-2018-16715
8.8HIGH
What is CVE-2018-16715?
A security vulnerability has been identified in Absolute Software CTES Windows Agent prior to version 1.0.0.1479, where insufficient security permissions on the %ProgramData%\CTES directory and its sub-folders could allow low-privileged user accounts to gain write access. This may lead to unauthorized actions, including the replacement of executable (EXE) or dynamically loadable library (DLL) files, potentially granting elevated SYSTEM user access. Additionally, configuration control files or data files within this folder could similarly be tampered with, ultimately affecting the behavior of the service process.