The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.
| Software | From | Fixed in |
|---|---|---|
| td-agent-builder_project / td-agent-builder | - | 2020-12-18 |
| debian / debian_linux | 10.0 | 10.0.x |