CVE-2022-47529

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/03/2023
Last modified:
11/04/2024

Description

Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:netwitness:*:*:*:*:*:*:*:* 12.2 (excluding)