First published: Wed Apr 17 2019(Updated: )
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Beyondtrust Avecto Defendpoint | >=4.0<4.4.267.0 | |
Beyondtrust Avecto Defendpoint | >=5.0<5.1.149.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10959 is a vulnerability in Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 that allows an attacker to elevate their privileges by modifying environment variables.
CVE-2018-10959 works by exploiting an untrusted search path vulnerability in Avecto Defendpoint, where an attacker can modify environment variables to trigger automatic elevation of their process launch.
CVE-2018-10959 has a severity rating of 7.5 (High).
Avecto Defendpoint versions prior to 4.4 SR6 and 5 prior to 5.1 SR1 are affected by CVE-2018-10959.
To fix CVE-2018-10959, it is recommended to update Avecto Defendpoint to version 4.4 SR6 or version 5.1 SR1 or newer.