QID 376976

QID 376976: Snow Agent Arbitrary Code Execution Vulnerability

Snow Inventory Agent for Windows is part of the Snow Inventory solution and is used for inventory of Windows computers.

Affected Products
Snow Agent for Windows version 5.0.0 to 6.7.1
QID Detection Logic(Authenticated):
It checks for vulnerable version of Snow Agent by checking windows registry path .

If exploited, this vulnerability could allow an attacker who already has low level, local-user privileges to overwrite existing files on the system.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    Install or update to Snow Inventory Agent 6.7.2 For more details refer SNOW AGENT

    CVEs related to QID 376976

    Software Advisories
    Advisory ID Software Component Link
    Snow Agent URL Logo community.snowsoftware.com/s/group/0F91r000000QUhPCAW/news-updates