First published: Mon Jul 29 2024(Updated: )
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Hydra Sdk Windows Service. The issue lies in the lack of proper permissions set on a folder created by the service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software | Affected Version | How to fix |
---|---|---|
Panda Dome |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-24-1015 is categorized as a privilege escalation vulnerability.
To fix ZDI-24-1015, ensure that you install the latest security updates provided by Panda Security for Dome.
Users of Panda Security Dome who have not applied relevant software updates may be affected by ZDI-24-1015.
No, ZDI-24-1015 requires local access to the system to exploit the vulnerability.
If you suspect exploitation of ZDI-24-1015, immediately review system access logs and apply security patches.