Local Attacker Can Escalate Privileges via Recheck Compliance Status Component
CVE-2024-22795

7HIGH

Key Information:

Vendor

Forescout

Vendor
CVE Published:
8 February 2024

What is CVE-2024-22795?

A vulnerability has been identified in Forescout SecureConnector, specifically version 11.3.06.0063, which relates to insecure permissions. This flaw enables a local attacker to gain elevated privileges through the Recheck Compliance Status component. Consequently, the attacker can potentially bypass security protocols and manipulate system settings, posing significant risks to the affected deployment. Immediate action is recommended to mitigate the effects of this vulnerability.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.