ITM Windows Agent Insecure Filesystem Permissions
Description
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local unprivileged users can disrupt agent monitoring in Proofpoint ITM Windows Agent prior to 7.14.3.
Vulnerability
The Proofpoint Insider Threat Management (ITM) Agent for Windows, versions prior to 7.14.3, contains an insecure filesystem permissions vulnerability [1]. This allows local unprivileged users to interfere with the agent's event reporting and monitoring capabilities. Agents for macOS, Linux, and Cloud are unaffected [1].
Exploitation
An attacker needs only local access to the Windows machine with unprivileged user credentials [1]. No special privileges or user interaction beyond authentication is required. The vulnerability is exploited by modifying or accessing files in the agent's installation directory due to overly permissive access control lists (ACLs) (implied by the nature of insecure filesystem permissions) [1].
Impact
Successful exploitation can cause a denial of service (disruption of agent monitoring) with high availability impact, as per CVSS v3.1 score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) [1]. The attacker cannot read, modify, or delete arbitrary data; they can only disrupt the agent's operation.
Mitigation
Proofpoint released the fixed version 7.14.3 of the ITM Windows Agent, available through the customer support portal [1]. All users should upgrade to 7.14.3 or later. No workarounds are provided in the reference, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<7.14.3+ 1 more
- (no CPE)range: <7.14.3
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.