First published: Mon Oct 12 2015(Updated: )
EMC RSA Web Threat Detection before 5.1 SP1 allows local users to obtain root privileges by leveraging access to a service account and writing commands to a service configuration file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Web Threat Detection | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4548 is classified as a critical vulnerability due to the potential for local users to gain root privileges.
To fix CVE-2015-4548, upgrade the RSA Web Threat Detection software to version 5.1 SP1 or later.
Local users with access to service accounts on EMC RSA Web Threat Detection versions prior to 5.1 SP1 are affected by CVE-2015-4548.
CVE-2015-4548 is a privilege escalation vulnerability that allows local users to gain unauthorized access to root privileges.
Yes, there are known exploit methods that can be utilized to take advantage of CVE-2015-4548 if the software is unpatched.