CVE-2017-6554: Input Validation
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACTNEWFILESENT action.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Quest Privilege Manager (pmmasterd)to a version that resolves this vulnerability.Fixed in 6.0.0.061
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6554?
CVE-2017-6554 has a high severity rating as it allows remote attackers to execute arbitrary code with root privileges.
How do I fix CVE-2017-6554?
To fix CVE-2017-6554, upgrade Quest Privilege Manager to version 6.0.0.061 or later.
What versions of Quest Privilege Manager are affected by CVE-2017-6554?
CVE-2017-6554 affects Quest Privilege Manager versions prior to 6.0.0.061, specifically versions 6.0.0-27 and 6.0.0-50.
What type of vulnerability is CVE-2017-6554?
CVE-2017-6554 is classified as an arbitrary file write vulnerability.
Can CVE-2017-6554 be exploited remotely?
Yes, CVE-2017-6554 can be exploited remotely by attackers to gain unauthorized access.