The C:WindowsTempAgent.Package.AvailabilityAgent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:WindowsTempAgent.Package.Availability folder inherits permissions from C:WindowsTemp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Agent_package_availability | Atera | * | 0.15.0.0 (excluding) |