CVE-2023-29486: Critical severity heimdal security thor vulnerability
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection capabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29486?
The severity of CVE-2023-29486 is high due to the potential for arbitrary code execution and sensitive information exposure.
How do I fix CVE-2023-29486?
To fix CVE-2023-29486, upgrade Heimdal Thor agent to version 3.7.0 or later.
What versions of Heimdal Thor are affected by CVE-2023-29486?
Heimdalsecurity Thor agent versions 3.4.2 and earlier than 3.7.0 are affected by CVE-2023-29486.
Is CVE-2023-29486 limited to Windows?
CVE-2023-29486 specifically affects Heimdal Thor agent on Windows systems.
What type of issue is CVE-2023-29486?
CVE-2023-29486 allows attackers to bypass USB access restrictions and execute arbitrary code.