Race Condition
Published Apr 18, 2023
7.0
HIGHCVSS 3.1
EPSS 0.13%
Description
A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during uninstallation of the Qualys Cloud Agent for Windows. Attackers may gain SYSTEM level privileges on that asset to run arbitrary commands.
At the time of this disclosure, versions before 4.0 are classified as End of Life.
Affected products
-
- Version 3.1.3.34StatusaffectedConstraints<4.5.3.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Qualys | Cloud Agent | unaffected |
|
- ≥ 3.1.3.34 · < 4.5.3.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.5.3.1 of the Qualys Cloud Agent for Windows
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31853 Advisory
- https://www.qualys.com/security-advisories/ vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31853 | Advisory | |
| https://www.qualys.com/security-advisories/ | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.