Vulnerability Description
JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://community.jumpcloud.com/t5/jumpcloud-product-news/bd-p/releases
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024
- https://community.jumpcloud.com/t5/jumpcloud-product-news/bd-p/releases
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024
FAQ
What is CVE-2023-26603?
CVE-2023-26603 is a vulnerability with a CVSS score of 5.9 (MEDIUM). JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.
How severe is CVE-2023-26603?
CVE-2023-26603 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26603?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.