← Back

CVE-2021-22159

nvd nist
Published: Jan 26, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. Agents for MacOS, Linux, and ITM Cloud are not affected.

Affected (8)

1 product
Insider Threat Management
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Proofpoint
Before 7.4.3
From 7.10.0 to 7.10.2
From 7.11.0.0 to 7.11.0.25
From 7.5.0 to 7.5.4
From 7.6.0 to 7.6.5
From 7.7.0 to 7.7.5
From 7.8.0 to 7.8.4
From 7.9.0 to 7.9.3

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.