CVE-2023-26236

An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:watchguard:epp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epp:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:watchguard:edr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:edr:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:watchguard:epdr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epdr:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:watchguard:panda_ad360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:panda_ad360:-:*:*:*:*:*:*:*

History

11 Oct 2023, 14:00

Type Values Removed Values Added
First Time Watchguard panda Ad360
Watchguard edr Firmware
Watchguard epp
Watchguard
Watchguard edr
Watchguard panda Ad360 Firmware
Watchguard epp Firmware
Watchguard epdr Firmware
Watchguard epdr
References (CONFIRM) https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - (CONFIRM) https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00004 - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:h:watchguard:epdr:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:panda_ad360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:edr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:panda_ad360:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:edr:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:epp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:epp:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:epdr_firmware:*:*:*:*:*:*:*:*

05 Oct 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-05 01:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-26236

Mitre link : CVE-2023-26236

CVE.ORG link : CVE-2023-26236


JSON object : View

Products Affected

watchguard

  • edr_firmware
  • panda_ad360
  • epp_firmware
  • panda_ad360_firmware
  • epp
  • epdr
  • epdr_firmware
  • edr