CVE-2022-47529
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-47529.
What is the severity of CVE-2022-47529?
The severity of CVE-2022-47529 is medium.
What does CVE-2022-47529 allow attackers to do?
CVE-2022-47529 allows local and admin Windows user accounts to modify the endpoint agent service configuration, potentially enabling unauthorized code execution.
Which version of RSA NetWitness Platform is affected by CVE-2022-47529?
RSA NetWitness Platform version up to but excluding 12.2 is affected by CVE-2022-47529.
How can I fix the vulnerability described in CVE-2022-47529?
Upgrade to RSA NetWitness Platform version 12.2 or higher to fix the vulnerability described in CVE-2022-47529.