XProtect Configuration API security vulnerability and mitigation
We have identified three related vulnerabilities in the XProtect Configuration API that can cause an elevation of privileges and affect the Management Server's security if exploited in XProtect Corporate, Expert, Professional+, Express+, and Essential+.
This issue can be reproduced using the Configuration API sample code found in the MIP SDK and results in a failure to perform the correct security check when modifying security settings.
Implications:
Missing authorization validation when changing device properties (V. 10.1 onwards).
Incorrect authorization validation when changing role security (V. 11.1 onwards).
Incorrect authorization validation when changing user-defined event properties (V. 12.2 onwards).
Affected product versions:
XProtect Corporate, Expert, Professional+, Express+, and Essential+, version 2016 R1 (10.0a) and newer.
Recommended steps:
To mitigate this security vulnerability, users are required to install the cumulative patch that matches the XProtect version their installation is running. Updates are available for the following versions:
KB 2887: XProtect 2016 R2 (10.1a) cumulative patch installers
KB 2888: XProtect 2016 R3 (10.2a) cumulative patch installers
KB 3051: XProtect 2017 R1 (11.1a) cumulative patch installers
KB 3275: XProtect 2017 R2 (11.2a) cumulative patch installers
KB 4219: XProtect 2017 R3 (11.3a) cumulative patch installers
KB 4220: XProtect 2018 R1 (12.1a) cumulative patch installers
KB 6211: XProtect 2018 R2 (12.2a) cumulative patch installers
KB 7805: XProtect 2018 R3 (12.3a) cumulative patch installers
KB 11717: XProtect 2019 R1 (13.1a) cumulative patch installers
Note: If you are using XProtect 2016 (10.0a), we recommend you to upgrade to at least version 2016 R2 (10.1a) or later, as the hotfix for the issue "XProtect Configuration API security vulnerability" is not included in the cumulative patch for 2016 (10.0a) — version 2016 (10.0a) is no longer supported as of March 2019.
Article Number
000002010