This document addresses the specific challenges associated with the privilege escalation vulnerability in Endpoint Central agent.
Severity: High
Attack Vector: Local
Fixed build:
For versions 11.3.2416.18 or below, upgrade to version 11.3.2416.20
For versions 11.3.2428.02 or below, upgrade to 11.3.2428.04
Release date: 30-Aug-2024
Reported by: Krzysztof via ZohoCorp Bug bounty program
Under certain conditions, a standard user can exploit the Device Temporary Access tool by interacting with its service to launch it with SYSTEM privileges, enabling further privilege escalation.
Upgrading to the latest version is strongly advised due to this vulnerability's severity. To upgrade, follow the below steps:
For any further questions or concerns about this, please write to our support team.