The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://www.vsecurity.com/download/advisories/20171026-1.txt | issue tracking release notes third party advisory |
http://www.securitytracker.com/id/1039679 | issue tracking release notes vdb entry third party advisory |