HIGH
Sensu, Inc
Published Jul 13, 2018
8.8
HIGHCVSS 3.0
EPSS 1.22%
Description
Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may execute code in context of Sensu service account. This attack appear to be exploitable via Unprivileged user may place an arbitrary DLL in the c:\opt\sensu\embedded\bin directory in order to exploit standard Windows DLL load order behavior. This vulnerability appears to have been fixed in 1.4.2-3 and later.
Affected products
No data.
- < 1.4.2-3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://docs.sensu.io/sensu-core/1.4/changelog/#core-v1-4-2 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-1881 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.sensu.io/sensu-core/1.4/changelog/#core-v1-4-2 | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-1881 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 13, 2018
Updated Sep 17, 2024
Reserved Jul 13, 2018
Link CVE-2018-1000209
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-1881 Assigner mitre
Published Jul 13, 2018
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2018-1881