
A zero-day vulnerability in the Windows installer of Atera remote monitoring and management software could act as a springboard to launch a privilege escalation attack.
Discovered by Mandiant on February 28, 2023, this flaw has been assigned identifiers CVE-2023-26077 and CVE-2023-26078, and the issue was fixed in versions 1.8.3.7 and 1.8.4.9 released by Atera on April 17, 2023 and June 26, 2023, respectively. I was.
“The ability to initiate operations from the NT AUTHORITY\SYSTEM context can pose potential security risks if not properly managed,” said security researcher Andrew Oliveau. “For example, a misconfigured custom action running as NT AUTHORITY\SYSTEM could be exploited by an attacker to perform a local privilege escalation attack.”
Successful exploitation of such a vulnerability could open the way to arbitrary code execution with elevated privileges.
Both flaws exist in the repair functionality of the MSI installer and can lead to scenarios where the operation is triggered from the NT AUTHORITY\SYSTEM context even if the operation was initiated by a standard user.
According to a Google-owned threat intelligence company, Atera Agent is susceptible to local privilege escalation attacks and can be exploited through a DLL hijack (CVE-2023-26077) to gain a command prompt as the NT AUTHORITY\SYSTEM user.

CVE-2023-26078, on the other hand, involves “executing a system command that triggers the Windows Console Host (conhost.exe) as a child process,” which opens a “command window” that, “when run with elevated privileges, may allow an attacker to exploit this command window to perform local privilege escalation attacks.”
“Misconfigured custom actions can be easily identified and exploited, and as a result can pose significant security risks to your organization,” said Oliveau. “It is imperative that software developers thoroughly review their custom actions to prevent attackers from hijacking NT AUTHORITY\SYSTEM operations caused by MSI remediation.”
Shielding Against Insider Threats: Mastering SaaS Security Posture Management
Worried about insider threats? We’ve got you covered! Join us for this webinar to explore practical strategies and proactive security secrets using SaaS Security Posture Management.
join today
This disclosure comes as Kaspersky sheds more light on a critical privilege escalation flaw in Windows (CVE-2023-23397, CVSS score: 9.8), which is now fixed. This flaw is being actively exploited in the wild by threat actors using specially crafted Outlook tasks, messages, or calendar events.
Microsoft had previously disclosed that a Russian nation-state group had weaponized the bug since April 2022, but evidence collected by an antivirus vendor reveals that the actual exploitation attempt was carried out by an unknown attacker targeting governments and critical infrastructure entities in Jordan, Poland, Romania, Turkey and Ukraine a month before its disclosure.