Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96925 | vdb entry third party advisory vendor advisory |
https://security.paloaltonetworks.com/CVE-2017-6356 | vendor advisory |