Loading
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server.
Use CWE-22, Ossec vendor hub and Ossec product page to widen CVE-2018-19666 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8447, CVE-2020-8445 and CVE-2020-8444 for nearby disclosures in the same product family.