CVE-2022-29594

eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:eginnovations:eg_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:eg_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:eg_rum_collectors:*:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:vm_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

13 Jun 2022, 13:50

Type Values Removed Values Added
References (MISC) https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0028/MNDT-2022-0028.md - (MISC) https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0028/MNDT-2022-0028.md - Exploit, Third Party Advisory
CWE CWE-281
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:a:eginnovations:vm_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:eg_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:eg_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:eginnovations:eg_rum_collectors:*:*:*:*:*:*:*:*

02 Jun 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-02 23:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-29594

Mitre link : CVE-2022-29594

CVE.ORG link : CVE-2022-29594


JSON object : View

Products Affected

eginnovations

  • eg_agent
  • vm_agent
  • eg_manager
  • eg_rum_collectors

microsoft

  • windows
CWE
CWE-281

Improper Preservation of Permissions