Vulnerability Description
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Itarian | Endpoint Manager Communication Client | < 7.0.42012.22030 |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2022-25153Third Party Advisory
- https://csirt.divd.nl/DIVD-2021-00037Third Party Advisory
- https://csirt.divd.nl/CVE-2022-25153Third Party Advisory
- https://csirt.divd.nl/DIVD-2021-00037Third Party Advisory
FAQ
What is CVE-2022-25153?
CVE-2022-25153 is a vulnerability with a CVSS score of 7.8 (HIGH). The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a...
How severe is CVE-2022-25153?
CVE-2022-25153 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25153?
Check the references section above for vendor advisories and patch information. Affected products include: Itarian Endpoint Manager Communication Client.