A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM privileges. This vulnerability is due to the .NET Agent Coordinator Service executing code with SYSTEM privileges. An attacker with local access to a device that is running the vulnerable agent could create a custom process that would be launched with those SYSTEM privileges. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system. This vulnerability is fixed in AppDynamics .NET Agent Release 21.7.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2021-08-18T19:50:12.469625Z
Updated: 2024-11-07T22:03:35.792Z
Reserved: 2021-06-15T00:00:00
Link: CVE-2021-34745
Vulnrichment
Updated: 2024-08-04T00:19:48.160Z
NVD
Status : Analyzed
Published: 2021-08-18T20:15:07.747
Modified: 2021-08-26T01:53:12.220
Link: CVE-2021-34745
Redhat
No data.