CVE-2024-57695

7.7

Agnitum · Outpost Security Suite

Agnitum Outpost Security Suite 7.5.3 and 7.6 contain a local arbitrary code execution vulnerability in the lock function.

Executive summary

Agnitum Outpost Security Suite versions 7.5.3 and 7.6 are vulnerable to local arbitrary code execution, posing a significant risk to system integrity.

Vulnerability

This vulnerability involves an issue within the lock function of the software that allows a local, unauthenticated attacker to execute arbitrary code on the host system.

Business impact

Successful exploitation allows an attacker with local access to execute arbitrary code, potentially leading to a full system compromise. With a CVSS score of 7.7, this is a High severity vulnerability that could be leveraged to escalate privileges or exfiltrate sensitive data from the affected host.

Remediation

Immediate Action: Update to Agnitum Outpost Security Suite version 8.0 (4164.652.1856) or later to remediate the flaw.

Proactive Monitoring: Audit system logs for unauthorized access or suspicious process execution associated with the security suite service.

Compensating Controls: Restrict local access to the system to authorized personnel only to prevent exploitation by malicious actors.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the High severity of this vulnerability, administrators should prioritize updating affected systems to version 8.0 immediately. While local access is required for exploitation, the impact of arbitrary code execution necessitates prompt patching to ensure continued system security.

Sources