An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
http://secureanywhere.com | product |
http://webroot.com | product |
https://www.spenceralessi.com/CVEs/2023-05-10-Webroot-SecureAnywhere/ | third party advisory |