First published: Thu Jul 21 2022(Updated: )
This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution rights on the victim machine prior to successful exploitation.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Elements Endpoint Protection | ||
Microsoft Windows |
FIX No User action is required. The required fix has been published through automatic update channel with UlcoreWin database on 2022-07-19_01
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28877 is a vulnerability that allows a local user to delete arbitrary files in the system and bypass security protection on affected F-Secure & WithSecure Windows endpoint products, potentially resulting in local privilege escalation.
F-Secure Elements Endpoint Protection is affected by CVE-2022-28877.
To exploit CVE-2022-28877, the attacker must have code execution rights on the victim machine prior to successfully deleting arbitrary files and bypassing security protection.
CVE-2022-28877 has a severity value of 6.7, which is considered medium.
To protect your system from CVE-2022-28877, ensure that you have the latest security updates and patches for the affected F-Secure Elements Endpoint Protection software.