CVE-2023-26236

An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:watchguard:epp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epp:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:watchguard:edr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:edr:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:watchguard:epdr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epdr:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:watchguard:panda_ad360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:panda_ad360:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:50

Type Values Removed Values Added
References () https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - Vendor Advisory () https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - Vendor Advisory

20 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-269

11 Oct 2023, 14:00

Type Values Removed Values Added
First Time Watchguard panda Ad360 Firmware
Watchguard epp
Watchguard edr
Watchguard epp Firmware
Watchguard epdr Firmware
Watchguard panda Ad360
Watchguard epdr
Watchguard
Watchguard edr Firmware
References (CONFIRM) https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - (CONFIRM) https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - Vendor Advisory
CPE cpe:2.3:o:watchguard:panda_ad360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:epdr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epp:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epdr:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:edr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:edr:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:epp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:panda_ad360:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-noinfo

05 Oct 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-05 01:15

Updated : 2024-11-21 07:50


NVD link : CVE-2023-26236

Mitre link : CVE-2023-26236

CVE.ORG link : CVE-2023-26236


JSON object : View

Products Affected

watchguard

  • edr
  • panda_ad360_firmware
  • panda_ad360
  • epp
  • epdr
  • epdr_firmware
  • edr_firmware
  • epp_firmware
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management