Security Advisory

CVE-2022-27905

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-27 13:59:10
Last updated 2024-08-03 05:41:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.