Exploitation Summary
EIP tracks 2 public exploits for CVE-2022-47529. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit targets RSA NetWitness Platform 12.2 by manipulating insecure Win32 memory objects to modify the endpoint agent service configuration, allowing local users to stop the agent or execute arbitrary commands. The PoC demonstrates ACL modification to deny access to the 'Everyone' group, bypassing tamper-protection features.
Description
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.
Exploits (2)
This exploit targets RSA NetWitness Platform 12.2 by manipulating insecure Win32 memory objects to modify the endpoint agent service configuration, allowing local users to stop the agent or execute arbitrary commands. The PoC demonstrates ACL modification to deny access to the 'Everyone' group, bypassing tamper-protection features.
This PoC exploits an incorrect access control vulnerability (CVE-2022-47529) in RSA NetWitness Platform EDR Agent, allowing local users to tamper with the service by modifying insecure Win32 memory event objects. The exploit can stop the agent or execute arbitrary commands, bypassing tamper-protection features.
References (8)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H