CVE Database
/

CVE-2017-2290

Back to search

CVE-2017-2290

Published: Mar 3, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.

VendorProductVersions

Puppet

mcollective-puppet-agent plugin

affected
1.12.0

References

96583
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now