vendor:
Panda Endpoint Administration Agent
by:
Kyriakos Economou
7,8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Panda Endpoint Administration Agent
Affected Version From: Panda Endpoint Administration Agent < v7.50.00
Affected Version To: Panda Endpoint Administration Agent v7.50.00
Patch Exists: YES
Related CWE: CVE-2016-3943
CPE: a:panda_security:panda_endpoint_administration_agent
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Privilege Escalation in Panda Endpoint Administration Agent
Panda Endpoint Administration Agent v7.30.2 allows a local attacker to elevate his privileges from any account type (Guest included) and execute code as SYSTEM, thus completely compromising the affected host.
Mitigation:
Restrict access to the installation directory of the application and its subdirectories.