6
CVSSv3

CVE-2023-6253

Published: 22/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 6 | Impact Score: 5.2 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local malicious user to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortra digital guardian agent

Exploits

The uninstaller in Fortra Digital Guardian Agent versions prior to 794 suffers from a cross site scripting vulnerability Additionally, the Agent Uninstaller handles sensitive data insecurely and caches the Uninstall key in memory This key can be used to stop or uninstall the application This allows a locally authenticated attacker with adminis ...