WatchGuard Terminal Services Agent Privilege Escalation Vulnerability
Vulnerability
A local privilege escalation vulnerability has been identified in the WatchGuard Terminal Services Agent for Windows, specifically in versions 12.0 through 12.10. The issue arises because the application does not correctly set directory permissions when installed in a non-default location. This flaw could enable an authenticated local attacker to gain SYSTEM privileges on the affected system.
Impact
Exploitation of this vulnerability allows authenticated local attackers to escalate privileges to the SYSTEM level.
Remediation
Users can upgrade to WatchGuard Terminal Services Agent version 12.11.2 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
