Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Apr 17, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
References