peter bassill · operator
$ cve CVE-2022-47529 JSON

CVE-2022-47529 EXPLOIT

6.7
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.

Scoring

CVSS6.7 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS1.57% — more likely to be exploited than 75% of all CVEs
On CISA KEVno
Public exploityes
Published2023-03-28
Last modified2026-06-17

Affected (1)

VendorProduct
rsanetwitness

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD