Important Security Patch: 2020-04-24

Affected Service Providers & Systems

Liongard Agents below version 1.9.76 on Windows systems.

👍

Liongard Agent Version

The updated Agent version displayed in Liongard is Version 1.9.76.

In the MSI Installer logs, you may see the full version number, 1.9.76.2.

Issue Summary

The permissions applied to certain folders created during the install of the On-premise Liongard Agent were not restrictive enough. This created the possibility of a user with login access to the server gaining access to these folders. With this access, the user could have potentially disrupted or modified the program files.

The Liongard team was made aware of the issue by two of our partners, and after investigating and gaining a full understanding of the issue, we have issued a revised MSI installer that uses a more restrictive set of permissions for the folders in question.

Issue Scope

If you have used the Liongard Agent MSI installer prior to this update, then your Agents are likely impacted.

To verify:

  • Log into Liongard and navigate to Admin > Agents
  • Sort Agents by the Version column
1448

Any Windows Agents with a version less than 1.9.76 are affected and require action. Linux Agents are not impacted.

Issue Mitigation

Upgrade your Agents to version 1.9.76 or higher.

The MSI installer, available for download from your Liongard instance, will provide the latest Agent version. Follow our Upgrade a Liongard Agent documentation

If you are interested in additional details, please contact us at [email protected].