CVE-2018-10959

HIGH

Avecto Defendpoint 4.0-4.4.267.0 - Untrusted Search Path via Environment Variable Manipulation

Title source: llm
STIX 2.1

Description

Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

Scores

CVSS v3 7.5
EPSS 0.0160
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-426
Status published
Products (1)
beyondtrust/avecto_defendpoint 4.0 - 4.4.267.0
Published Apr 17, 2019
Tracked Since Feb 18, 2026