CVE-2023-29818
CVSS 5.5 MEDIUM

Webroot SecureAnywhere — Permissive Allowlist Bypass

Affected Product
Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and earlier
CWE Classification
CWE-183 — Permissive List of Allowed Inputs
Attack Vector
Local
Privileges Required
Low (non-admin)
Impact
High impact on system integrity
Published
May 12, 2023

Description

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin. A local attacker can match their payload to a file name, file path, and file size of one of the files contained within the default allowlist to bypass protections.

Technical Details

The default allowlist feature in Webroot SecureAnywhere stores its configuration with non-administrative privileges. This means a local attacker, even without admin access, can craft malicious files that match the filename, file path, and file size of legitimately allowlisted files. By mimicking these attributes, the attacker's payload evades detection and bypasses the endpoint protection entirely.

CVE-2023-29819
CVSS 5.5 MEDIUM

Webroot SecureAnywhere — Improper Access Control / Registry Disclosure

Affected Product
Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and earlier
CWE Classification
CWE-269 — Improper Privilege Management
Attack Vector
Local
Privileges Required
Low (non-admin)
Impact
High impact on confidentiality
Published
May 12, 2023

Description

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. A local attacker, as a non-administrator, can read the registry containing the default allowlist.

Technical Details

This vulnerability stems from improper access control on the Windows registry keys used by Webroot SecureAnywhere. The registry containing the default allowlist is readable by non-administrator users, exposing sensitive configuration data. By reading this registry information, a local attacker can determine exactly which files are allowlisted and then craft payloads specifically designed to bypass the endpoint protection by exploiting this knowledge.

Disclosure Timeline
2023
Vulnerabilities discovered in Webroot SecureAnywhere Endpoint Protection during security research
May 10, 2023
Advisory published on spenceralessi.com
May 12, 2023
CVE-2023-29818 and CVE-2023-29819 published in NVD
May 24, 2023
NIST initial analysis completed with CVSS scoring
Back to Home