Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Vulnerability
A local privilege escalation vulnerability has been identified in Action1 Agent versions through 5.216.617.1 on Windows. This vulnerability arises from the product loading an OpenSSL configuration file from an unsecured location, allowing local attackers who can execute low-privileged code to escalate privileges and execute arbitrary code with SYSTEM rights.
Impact
Exploitation of this vulnerability allows for local privilege escalation, enabling a low-privileged user to execute code with SYSTEM privileges.
Remediation
Action1 has released a patch for this vulnerability in version 5.218.620.1. For endpoints still running versions prior to 5.218.620.1, Action1 recommends rebooting the system. If the issue persists, force uninstall the existing Action1 Agent and reinstall the latest version from the Action1 download portal.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
