An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
http://secureanywhere.com | product |
http://webroot.com | product |
https://www.spenceralessi.com/CVEs/2023-05-10-Webroot-SecureAnywhere/ | third party advisory |