Description
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9232 | In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.388Z
Reserved: 2019-12-06T00:00:00.000Z
Link: CVE-2019-19620
No data.
Status : Modified
Published: 2019-12-06T16:15:11.187
Modified: 2026-06-17T02:26:57.887
Link: CVE-2019-19620
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-281
Improper Preservation of Permissions
EUVD