Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elevated privileges.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://endpoint.com | not applicable |
http://cybereason.com | vendor advisory |
https://www.cybereason.com/cybereason-vulnerability-disclosure | vendor advisory |