VYPR

Endpoint Agents

by Webroot Software

CVEs (2)

  • CVE-2020-5754CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

  • CVE-2020-5755HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.