Important Security Patch: 2020-04-24
Affected Service Providers & Systems
Liongard Agents below version 1.9.76 on Windows systems.
Liongard Agent Version
The updated Agent version displayed in Liongard is Version 1.9.76.
In the MSI Installer logs, you may see the full version number, 1.9.76.2.
Issue Summary
The permissions applied to certain folders created during the install of the On-premise Liongard Agent were not restrictive enough. This created the possibility of a user with login access to the server gaining access to these folders. With this access, the user could have potentially disrupted or modified the program files.
The Liongard team was made aware of the issue by two of our partners, and after investigating and gaining a full understanding of the issue, we have issued a revised MSI installer that uses a more restrictive set of permissions for the folders in question.
Issue Scope
If you have used the Liongard Agent MSI installer prior to this update, then your Agents are likely impacted.
To verify:
- Log into Liongard and navigate to Admin > Agents
- Sort Agents by the Version column
Any Windows Agents with a version less than 1.9.76 are affected and require action. Linux Agents are not impacted.
Issue Mitigation
Upgrade your Agents to version 1.9.76 or higher.
The MSI installer, available for download from your Liongard instance, will provide the latest Agent version. Follow our Upgrade a Liongard Agent documentation
If you are interested in additional details, please contact us at [email protected].
Updated 12 months ago