CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.youtube.com/watch?v=B0VpK0poTco | third party advisory exploit |
https://mustafakemalcan.com/cyberark-epm-file-block-bypass-cve-2018-14894/ | third party advisory exploit |
https://www.exploit-db.com/exploits/46688/ | exploit vdb entry third party advisory |
http://packetstormsecurity.com/files/152489/CyberArk-EPM-10.2.1.603-Security-Restrictions-Bypass.html | exploit vdb entry third party advisory |