CVE-2022-47529 EXPLOIT
6.7
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.
Scoring
| CVSS | 6.7 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.57% — more likely to be exploited than 75% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-03-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| rsa | netwitness |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution | 2023-04-08 |
References
- http://seclists.org/fulldisclosure/2023/Mar/26
- http://seclists.org/fulldisclosure/2024/Apr/17
- https://community.netwitness.com/t5/netwitness-platform-security/nw-2023-04-netwitness-platform-security-advisory-cve-2022-47529/ta-p/696935
- https://github.com/hyp3rlinx/CVE-2022-47529
- https://hyp3rlinx.altervista.org/advisories/RSA_NETWITNESS_EDR_AGENT_INCORRECT_ACCESS_CONTROL_CVE-2022-47529.txt
- https://packetstormsecurity.com/files/171476/RSA-NetWitness-Endpoint-EDR-Agent-12.x-Incorrect-Access-Control-Code-Execution.html
- https://seclists.org/fulldisclosure/2023/Mar/16
- https://twitter.com/hyp3rlinx/status/1639335477839790105
- http://seclists.org/fulldisclosure/2023/Mar/26
- http://seclists.org/fulldisclosure/2024/Apr/17
- https://community.netwitness.com/t5/netwitness-platform-security/nw-2023-04-netwitness-platform-security-advisory-cve-2022-47529/ta-p/696935
- https://github.com/hyp3rlinx/CVE-2022-47529
- https://hyp3rlinx.altervista.org/advisories/RSA_NETWITNESS_EDR_AGENT_INCORRECT_ACCESS_CONTROL_CVE-2022-47529.txt
- https://packetstormsecurity.com/files/171476/RSA-NetWitness-Endpoint-EDR-Agent-12.x-Incorrect-Access-Control-Code-Execution.html
- https://seclists.org/fulldisclosure/2023/Mar/16
- https://twitter.com/hyp3rlinx/status/1639335477839790105
→ the Explorer · watch your stack · NVD