Windows Logon Integration Vulnerability in F5 BIG-IP APM Client
CVE-2018-5547
What is CVE-2018-5547?
The F5 BIG-IP APM client prior to version 7.1.7.1 for Windows employs the Legacy logon mode by default, which utilizes a SYSTEM account for network access. This implementation poses a security risk as it exposes a certificate user interface dialog box featuring a link to the certificate policy. Unprivileged users, upon clicking this link, gain the ability to open additional dialog boxes, potentially accessing the local machine's Windows Explorer and acquiring administrative privileges. This vulnerability arises specifically when the APM client is installed by an administrator on user machines, allowing local users to exploit the situation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP APM client for Windows Prior to version 7.1.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved