// For flags

CVE-2024-8424

WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
This issue affects EPDR: before 8.00.23.0000; Panda AD360: before 8.00.23.0000; Panda Dome: before 22.03.00.

This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Application Host Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.

*Credits: Anonymous
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-09-04 CVE Reserved
  • 2024-11-07 CVE Published
  • 2024-11-14 EPSS Updated
  • 2024-11-20 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
  • CAPEC-233: Privilege Escalation
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
WatchGuard
Search vendor "WatchGuard"
EPDR
Search vendor "WatchGuard" for product "EPDR"
< 8.00.23.0000
Search vendor "WatchGuard" for product "EPDR" and version " < 8.00.23.0000"
en
Affected
WatchGuard
Search vendor "WatchGuard"
Panda AD360
Search vendor "WatchGuard" for product "Panda AD360"
< 8.00.23.0000
Search vendor "WatchGuard" for product "Panda AD360" and version " < 8.00.23.0000"
en
Affected
WatchGuard
Search vendor "WatchGuard"
Panda Dome
Search vendor "WatchGuard" for product "Panda Dome"
< 22.03.00
Search vendor "WatchGuard" for product "Panda Dome" and version " < 22.03.00"
en
Affected