← Back to CVE List

CVE-2022-25153

Published: 2022-06-09T17:15Z
Last Modified: 2024-11-21T06:51Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt