Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in Action1 Agent versions through 5.216.617.1 on Windows. This vulnerability arises from the product loading an OpenSSL configuration file from an unsecured location, allowing local attackers who can execute low-privileged code to escalate privileges and execute arbitrary code with SYSTEM rights.

Impact

Exploitation of this vulnerability allows for local privilege escalation, enabling a low-privileged user to execute code with SYSTEM privileges.

Remediation

Action1 has released a patch for this vulnerability in version 5.218.620.1. For endpoints still running versions prior to 5.218.620.1, Action1 recommends rebooting the system. If the issue persists, force uninstall the existing Action1 Agent and reinstall the latest version from the Action1 download portal.

Added: Jun 6, 2025, 7:19 PM
Updated: Jun 6, 2025, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.