Vulnerability Description
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Red Cloak Windows Agent | < 2.0.7.9 |
Related Weaknesses (CWE)
References
- https://medium.com/%40CowbellSteve/secureworks-red-cloak-local-bypass-bfaed2be40
- https://www.secureworks.com/resources/ds-aetd-red-cloak-data-sheetVendor Advisory
- https://medium.com/%40CowbellSteve/secureworks-red-cloak-local-bypass-bfaed2be40
- https://www.secureworks.com/resources/ds-aetd-red-cloak-data-sheetVendor Advisory
FAQ
What is CVE-2019-19620?
CVE-2019-19620 is a vulnerability with a CVSS score of 3.3 (LOW). In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to t...
How severe is CVE-2019-19620?
CVE-2019-19620 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19620?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Red Cloak Windows Agent.