The Rapid7 InsightAppSec broker suffers from a DLL...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 6, 2023
Description
Published by the National Vulnerability Database
Aug 19, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Apr 6, 2023
The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.
References