Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Link | Tags |
---|---|
https://github.com/NF-Security-Team/CVEs/blob/main/CVE-Cynet/Readme.md | third party advisory exploit |
https://github.com/advisories/GHSA-hmjw-7429-p2vc |