CVE-2022-36670

MEDIUM

Pcprotect Endpoint < 5.17.470 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://mrvar0x.com/2022/07/21/pcprotect-endpoint-tampering-exploit/

Scores

CVSS v3 6.7
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
pcprotect/endpoint < 5.17.470
Published Sep 06, 2022
Tracked Since Feb 18, 2026