CVE-2018-10959
HIGHAvecto Defendpoint 4.0-4.4.267.0 - Untrusted Search Path via Environment Variable Manipulation
Title source: llmDescription
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
https://hackandpwn.com/cve-2018-10959/
Various Sources x_refsource_misc
https://hackandpwn.com/assets/2019-04-17-cve-2018-10959/Defendpoint_Windows_Client_Release_Notes_4.4.267.0_SR6.pdf
Various Sources x_refsource_misc
https://hackandpwn.com/assets/2019-04-17-cve-2018-10959/Defendpoint_Windows_Client_Release_Notes_5.1.149.0_SR1.pdf
Various Sources x_refsource_misc
https://www.beyondtrust.com/docs/release-notes/privilege-management/windows-and-mac/windows/pm-windows-4-4-sr6.pdf
Various Sources x_refsource_misc
https://www.beyondtrust.com/docs/release-notes/privilege-management/windows-and-mac/windows/pm-windows-5-1.pdf
Scores
CVSS v3
7.5
EPSS
0.0160
EPSS Percentile
72.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-426
Status
published
Products (1)
beyondtrust/avecto_defendpoint
4.0 - 4.4.267.0
Published
Apr 17, 2019
Tracked Since
Feb 18, 2026