QID 375648
Date Published: 2021-07-15
QID 375648: Centrify Service Suite agent (DirectControl) Privilege Escalation Vulnerability
Centrify Service Suite agent DC includes instructions for installing all identity and privilege management, audit and monitoring service, and multi-factor authentication components
Affected Version:
Centrify Service Suite agent (DirectControl) versions prior to 2020.1
Centrify Service Suite agent (DirectControl) versions prior to 5.7.1
QID Detection Logic (Authenticated):
On Linux systems, this QID detects vulnerable CentrifyDC versions by sending adinfo --version command.
Successful exploitation can result in a heap-based buffer overflow, which allows privilege escalation.
Solution
Centrify has relesed fixes for this vulnerability in version 2020.1 and 5.7.1 to remediate this vulnerability.
Vendor References
CVEs related to QID 375648
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-3156 |
|