CVE-2023-26236: High severity watchguard epp firmware vulnerability
Published Oct 5, 2023
·Updated
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
Affected Software
16 affected components
WatchGuard Epp Firmware<8.00.22.0010
WatchGuard Epp
WatchGuard Edr Firmware<8.00.22.0010
WatchGuard Edr
WatchGuard Epdr Firmware<8.00.22.0010
WatchGuard EPDR
WatchGuard Panda Ad360 Firmware<8.00.22.0010
WatchGuard Panda Ad360
All of the following
WatchGuard Epp
WatchGuard Epp Firmware<8.00.22.0010
All of the following
WatchGuard Edr
WatchGuard Edr Firmware<8.00.22.0010
All of the following
WatchGuard EPDR
WatchGuard Epdr Firmware<8.00.22.0010
All of the following
WatchGuard Panda Ad360
WatchGuard Panda Ad360 Firmware<8.00.22.0010
Event History
Oct 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in WatchGuard EPDR?
The vulnerability ID for this issue in WatchGuard EPDR is CVE-2023-26236.
2
What is the severity of CVE-2023-26236?
The severity of CVE-2023-26236 is high with a severity value of 7.8.
3
Which software versions are affected by CVE-2023-26236?
The affected software versions are WatchGuard EPDR 8.0.21.0002 up to exclusive version 8.00.22.0010.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a crafted message to a named pipe, leading to a local privilege escalation on Windows.
5
Is WatchGuard EPP or WatchGuard EDR vulnerable to CVE-2023-26236?
No, WatchGuard EPP and WatchGuard EDR are not vulnerable to CVE-2023-26236.