#VU105921 Security features bypass in Security QRadar EDR - CVE-2024-45644 

 

#VU105921 Security features bypass in Security QRadar EDR - CVE-2024-45644

Published: March 21, 2025


Vulnerability identifier: #VU105921
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-45644
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Security QRadar EDR
Software vendor:
IBM Corporation

Description

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to software allows SMB file downloads, restricted to Administrator and Responder accounts. A local privileged user can bypass implemented security restrictions and download malicious files to the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links