CVE-2023-26236

An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
watchguardepp_firmware
𝑥
< 8.00.22.0010
watchguardedr_firmware
𝑥
< 8.00.22.0010
watchguardepdr_firmware
𝑥
< 8.00.22.0010
watchguardpanda_ad360_firmware
𝑥
< 8.00.22.0010
𝑥
= Vulnerable software versions