First published: Wed Nov 22 2023(Updated: )
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
Credit: 551230f0-3615-47bd-b7cc-93e92e730bbf
Affected Software | Affected Version | How to fix |
---|---|---|
Fortra Digital Guardian Agent | <7.9.4 |
The vendor provides an updated Agent version 7.9.4 which can be downloaded at the vendor's support page: https://www.digitalguardian.com/services/support https://www.digitalguardian.com/services/support
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6253 is a vulnerability in Digital Guardian's Agent that allows a local attacker to retrieve the uninstall key and remove the software.
CVE-2023-6253 has a medium severity with a severity value of 6.
A local attacker can exploit CVE-2023-6253 by extracting the uninstaller key from the memory of the uninstaller file.
Digital Guardian's Agent before version 7.9.4 is affected by CVE-2023-6253.
To fix CVE-2023-6253, upgrade to version 7.9.4 or a later version of Digital Guardian's Agent.