CVE-2018-10959: High severity beyondtrust avecto defendpoint vulnerability
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10959?
CVE-2018-10959 is a vulnerability in Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 that allows an attacker to elevate their privileges by modifying environment variables.
How does CVE-2018-10959 work?
CVE-2018-10959 works by exploiting an untrusted search path vulnerability in Avecto Defendpoint, where an attacker can modify environment variables to trigger automatic elevation of their process launch.
What is the severity of CVE-2018-10959?
CVE-2018-10959 has a severity rating of 7.5 (High).
Which versions of Avecto Defendpoint are affected by CVE-2018-10959?
Avecto Defendpoint versions prior to 4.4 SR6 and 5 prior to 5.1 SR1 are affected by CVE-2018-10959.
How can I fix CVE-2018-10959?
To fix CVE-2018-10959, it is recommended to update Avecto Defendpoint to version 4.4 SR6 or version 5.1 SR1 or newer.