CVE-2025-53841
中文标题:
(暂无数据)
英文标题:
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions pri...
漏洞描述
中文描述:
(暂无数据)
英文描述:
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore Agent process. Since Guardicore Agent runs with SYSTEM privileges, this permits an unprivileged user to fully elevate privileges to SYSTEM level in this manner.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Akamai | Guardicore Platform Agent | - | < 50.15.0 | - |
cpe:2.3:a:akamai:guardicore_platform_agent:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-53841 |
2025-12-11 03:30:09 | 2026-01-12 02:11:57 |
| NVD | nvd_CVE-2025-53841 |
2025-12-11 03:32:41 | 2026-01-12 02:27:52 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 3 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']