CVE-2024-36074

HIGH

CoSoSys Endpoint Protector <= 5.9.3 and Unify <= 7.0.6 - Remote Code Execution via EasyLock Dependency

Title source: llm
STIX 2.1

Description

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. An attacker with administrative access to the Endpoint Protector or Unify server can cause a client to acquire and execute a malicious file resulting in remote code execution.

Scores

CVSS v3 7.2
EPSS 0.0079
EPSS Percentile 51.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Published Jun 27, 2024
Tracked Since Feb 18, 2026