First published: Thu Oct 26 2017(Updated: )
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Remote Support | =15.2.1 | |
BeyondTrust Remote Support | =15.2.2 | |
BeyondTrust Remote Support | =16.1.1 | |
BeyondTrust Remote Support | =16.1.2 | |
BeyondTrust Remote Support | =16.1.3 | |
BeyondTrust Remote Support | =16.1.4 | |
BeyondTrust Remote Support | =16.2.1 | |
BeyondTrust Remote Support | =16.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5996 is considered a medium severity vulnerability due to its potential for DLL hijacking.
To fix CVE-2017-5996, update Bomgar Remote Support to versions 15.2.3, 16.1.5, or 16.2.4 or later.
CVE-2017-5996 affects several versions of Bomgar Remote Support, specifically versions 15.2.1, 15.2.2, 16.1.1 through 16.1.4, and 16.2.1 and 16.2.2.
CVE-2017-5996 is associated with DLL hijacking attacks that exploit weak permissions in the program data directory.
CVE-2017-5996 is a local vulnerability as it requires access to the affected system to exploit the weak permissions.