CVE-2023-6253: Saved Uninstall Key in Digital Guardian Agent Uninstaller
Published Nov 22, 2023
·Updated
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
Affected Software
1 affected component
Fortra Digital Guardian Agent<7.9.4
Remediation
Information
The vendor provides an updated Agent version 7.9.4 which can be downloaded at the vendor's support page: https://www.digitalguardian.com/services/support https://www.digitalguardian.com/services/support
Event History
Nov 22, 2023
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-6253?
CVE-2023-6253 is a vulnerability in Digital Guardian's Agent that allows a local attacker to retrieve the uninstall key and remove the software.
2
What is the severity of CVE-2023-6253?
CVE-2023-6253 has a medium severity with a severity value of 6.
3
How can a local attacker exploit CVE-2023-6253?
A local attacker can exploit CVE-2023-6253 by extracting the uninstaller key from the memory of the uninstaller file.
4
Which version of Digital Guardian's Agent is affected by CVE-2023-6253?
Digital Guardian's Agent before version 7.9.4 is affected by CVE-2023-6253.
5
Is there a fix available for CVE-2023-6253?
To fix CVE-2023-6253, upgrade to version 7.9.4 or a later version of Digital Guardian's Agent.