Description
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
References (4)
Core 4
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/175956/Fortra-Digital-Guardian-Agent-Uninstaller-Cross-Site-Scripting-UninstallKey-Cached.html
Exploit, Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2023/Nov/14
Exploit, Third Party Advisory
https://r.sec-consult.com/fortra
Product
https://www.fortra.com/security
Scores
CVSS v3
6.0
EPSS
0.0031
EPSS Percentile
22.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-922
Status
published
Products (1)
fortra/digital_guardian_agent
< 7.9.4
Published
Nov 22, 2023
Tracked Since
Feb 18, 2026