Atera Windows Installers Vulnerable to Critical Privilege Escalation Attacks

1 min read
Source: The Hacker News
Atera Windows Installers Vulnerable to Critical Privilege Escalation Attacks
Photo: The Hacker News
TL;DR Summary

Zero-day vulnerabilities in the Windows Installers for Atera's remote monitoring and management software have been discovered, posing a risk of privilege escalation attacks. The flaws, assigned CVE-2023-26077 and CVE-2023-26078, have been patched in Atera versions 1.8.3.7 and 1.8.4.9. The vulnerabilities allow for the execution of arbitrary code with elevated privileges and involve misconfigured Custom Actions running as NT AUTHORITY\SYSTEM. Exploitation of these weaknesses could lead to local privilege escalation attacks.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

84%

44270 words

Want the full story? Read the original article

Read on The Hacker News