CVE-2017-2290
03.03.2017, 15:59
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.Enginsight
Vendor | Product | Version |
---|---|---|
puppet | mcollective-puppet-agent | 1.12.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration