First published: Tue Jan 26 2021(Updated: )
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. Agents for MacOS, Linux, and ITM Cloud are not affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Insider Threat Management Windows | <7.4.3 | |
Proofpoint Insider Threat Management Windows | >=7.5.0<7.5.4 | |
Proofpoint Insider Threat Management Windows | >=7.6.0<7.6.5 | |
Proofpoint Insider Threat Management Windows | >=7.7.0<7.7.5 | |
Proofpoint Insider Threat Management Windows | >=7.8.0<7.8.4 | |
Proofpoint Insider Threat Management Windows | >=7.9.0<7.9.3 | |
Proofpoint Insider Threat Management Windows | >=7.10.0<7.10.2 | |
Proofpoint Insider Threat Management Windows | >=7.11.0.0<7.11.0.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-22159.
The severity of CVE-2021-22159 is high.
The Proofpoint Insider Threat Management Agent for Windows versions before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25, as well as versions 7.3 and earlier, are affected by CVE-2021-22159.
To fix the CVE-2021-22159 vulnerability, install one of the patched versions of the Proofpoint Insider Threat Management Agent for Windows, including versions 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, or 7.11.0.25.
You can find more information about CVE-2021-22159 on the Proofpoint website at the following links: [Proofpoint Security Advisories](https://www.proofpoint.com/us/security/security-advisories) and [PFPT-SA-2021-0001](https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0001).