CVE-2024-36075: Netwrix Cososys Endpoint

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain remote code execution as an administrator on an endpoint.

Affected products

  • Netwrix Cososys Endpoint: up to and including 5.9.3
  • Netwrix Cososys Unify: up to and including 7.0.6

Published 2024-06-27. Last modified 2026-06-17.