vendor:
Automox Agent
by:
Greg Foss
7.8
CVSS
HIGH
Local Privilege Escalation
CWE
Product Name: Automox Agent
Affected Version From: 31
Affected Version To: 33
Patch Exists: NO
Related CWE: CVE-2021-43326
CPE:
Platforms Tested: Windows 10
2021
Automox Agent 32 – Local Privilege Escalation
This exploit allows an attacker to escalate their privileges locally on a system running Automox Agent 32. By manipulating the agent's script files, the attacker can execute arbitrary commands with elevated privileges.
Mitigation:
Apply the vendor-provided patch or upgrade to a version that is not affected. Restrict access to the Automox Agent directory to trusted users only.