The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
| Software | From | Fixed in |
|---|---|---|
| beyondtrust / remote_support | 15.2.1 | 15.2.1.x |
| beyondtrust / remote_support | 15.2.2 | 15.2.2.x |
| beyondtrust / remote_support | 16.1.1 | 16.1.1.x |
| beyondtrust / remote_support | 16.1.2 | 16.1.2.x |
| beyondtrust / remote_support | 16.1.3 | 16.1.3.x |
| beyondtrust / remote_support | 16.1.4 | 16.1.4.x |
| beyondtrust / remote_support | 16.2.1 | 16.2.1.x |
| beyondtrust / remote_support | 16.2.2 | 16.2.2.x |