CVE-2022-43997 Information

Description

Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.exe SYSTEM process with PROCESS_ALL_ACCESS rights.

Reference

https://winternl.com/cve-2022-43997/ https://gist.github.com/jackullrich/21fcfe75aeb5e18c60b80e684b83d741

Share on: