Skip to main content

Milestone Security Advisory

XProtect Configuration API security vulnerability and mitigation

Last Updated: 1 minute read
LanguageEnglish

We have identified three related vulnerabilities in the XProtect Configuration API that can cause an elevation of privileges and affect the Management Server's security if exploited in XProtect Corporate, Expert, Professional+, Express+, and Essential+.

This issue can be reproduced using the Configuration API sample code found in the MIP SDK and results in a failure to perform the correct security check when modifying security settings.

Implications:

  1. Missing authorization validation when changing device properties (V. 10.1 onwards). 

  2. Incorrect authorization validation when changing role security (V. 11.1 onwards). 

  3. Incorrect authorization validation when changing user-defined event properties (V. 12.2 onwards).

Affected product versions:

XProtect Corporate, Expert, Professional+, Express+, and Essential+, version 2016 R1 (10.0a) and newer.

Recommended steps:

To mitigate this security vulnerability, users are required to install the cumulative patch that matches the XProtect version their installation is running. Updates are available for the following versions:

  •  KB 2887: XProtect 2016 R2 (10.1a) cumulative patch installers

  •  KB 2888: XProtect 2016 R3 (10.2a) cumulative patch installers

  •  KB 3051: XProtect 2017 R1 (11.1a) cumulative patch installers

  •  KB 3275: XProtect 2017 R2 (11.2a) cumulative patch installers

  •  KB 4219: XProtect 2017 R3 (11.3a) cumulative patch installers

  •  KB 4220: XProtect 2018 R1 (12.1a) cumulative patch installers

  •  KB 6211: XProtect 2018 R2 (12.2a) cumulative patch installers

  •  KB 7805: XProtect 2018 R3 (12.3a) cumulative patch installers

  •  KB 11717: XProtect 2019 R1 (13.1a) cumulative patch installers

 Note: If you are using XProtect 2016 (10.0a), we recommend you to upgrade to at least version 2016 R2 (10.1a) or later, as the hotfix for the issue "XProtect Configuration API security vulnerability" is not included in the cumulative patch for 2016 (10.0a) — version 2016 (10.0a) is no longer supported as of March 2019.

Article Number

000002010