CVE-2023-26236

EUVD-2023-30061
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
watchguardepp_firmware
𝑥
< 8.00.22.0010
watchguardedr_firmware
𝑥
< 8.00.22.0010
watchguardepdr_firmware
𝑥
< 8.00.22.0010
watchguardpanda_ad360_firmware
𝑥
< 8.00.22.0010
𝑥
= Vulnerable software versions