Vulnerabilities > CVE-2019-19620 - Improper Preservation of Permissions vulnerability in Dell RED Cloak Windows Agent
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |