Vulnerability Description
The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain remote code execution as an administrator on an endpoint.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://helpcenter.netwrix.com/bundle/z-kb-articles-salesforce/page/kA0Qk0000001
- https://helpcenter.netwrix.com/bundle/z-kb-articles-salesforce/page/kA0Qk0000001
FAQ
What is CVE-2024-36075?
CVE-2024-36075 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or...
How severe is CVE-2024-36075?
CVE-2024-36075 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36075?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.