CVE-2017-5996: Critical severity beyondtrust remote support vulnerability
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5996?
CVE-2017-5996 is considered a medium severity vulnerability due to its potential for DLL hijacking.
How do I fix CVE-2017-5996?
To fix CVE-2017-5996, update Bomgar Remote Support to versions 15.2.3, 16.1.5, or 16.2.4 or later.
What does CVE-2017-5996 affect?
CVE-2017-5996 affects several versions of Bomgar Remote Support, specifically versions 15.2.1, 15.2.2, 16.1.1 through 16.1.4, and 16.2.1 and 16.2.2.
What type of attack is CVE-2017-5996 associated with?
CVE-2017-5996 is associated with DLL hijacking attacks that exploit weak permissions in the program data directory.
Is CVE-2017-5996 a local or remote vulnerability?
CVE-2017-5996 is a local vulnerability as it requires access to the affected system to exploit the weak permissions.