An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.
The product, when opening a file or directory, does not sufficiently handle when the name is associated with a hard link to a target that is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ca_client_automation | Broadcom | 14.0 (including) | 14.0 (including) |
Ca_client_automation | Broadcom | 14.1 (including) | 14.1 (including) |
Ca_client_automation | Broadcom | 14.2 (including) | 14.2 (including) |
Ca_client_automation | Broadcom | 14.3 (including) | 14.3 (including) |