First published: Tue Sep 05 2023(Updated: )
IBM QRadar WinCollect Agent 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, is vulnerable to a local escalation of privilege attack that a normal user could utilize to gain SYSTEM permissions. IBM X-Force ID: 262542.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar WinCollect | >=10.0<10.1.7 | |
<=10.0 - 10.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-38736.
The title of this vulnerability is IBM QRadar WinCollect Agent when installed to run as ADMIN or SYSTEM is vulnerable to a local escalation of privilege.
The severity of CVE-2023-38736 is high with a score of 7.5.
IBM QRadar WinCollect Agent versions 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, are affected by this vulnerability.
An attacker with normal user privileges could exploit CVE-2023-38736 to gain SYSTEM permissions.