The GoTo Community is currently experiencing some technical issues affecting new posts and comments. You may need to reload the page you are on before you can post a comment. We are actively working with our service provider and apologize for the frustration.
Forum Discussion
HappyHippo
2 years agoContributor
Security Vulnerability within LMInfo.sys
Hi,
I have tried to log a support case but the page is constantly reloading therefore I need to post here.
Our endpoint security product has detected the lmiinfo.sys as being an potentially unsafe application. Having looked into this, we can see a PoC to exploit this vulnerability for privilege escalation to SYSTEM permissions. https://github.com/alfarom256/LogMeInPoCHandleDup
We have checked and there's no update available for the LogMeIn clients.
Could you please confirm when this will be patched and whether there's any action required on our side?
Files:
C:/Program Files (x86)/LogMeIn/x64/lmiinfo.sys EAC1B9E1848DC455ED780292F20CD6A0C38A3406
C:/Windows/System32/drivers/LMIInfo.sys EAC1B9E1848DC455ED780292F20CD6A0C38A3406
C:/Windows/System32/drivers/LMIInfo.sys.000.bak EAC1B9E1848DC455ED780292F20CD6A0C38A3406
Thanks,
37 Replies
- 2ARM52 years agoActive Contributor
Hi Glen,
I've only installed the update on one system so far, due to the issue I raised in my last post, but that system did pass an AV scan w/o a detection.
Best,
- GlennD2 years agoGoTo Manager
Hi, I am checking with the team on what the next course of action is. The update itself was quite minor and should have just resulted in the previous LMInfo.sys warning going away.
- SOSCOMP2 years agoNew Contributor
We have same issue and mos recent update for LogMein did not fix it. We use ESET Endpoint and their support said it was LMI issue-thanks
- SOSCOMP2 years agoNew Contributor
Hi did your get a resolution to this? We have same issue -using ESET Endpoint
- 2ARM52 years agoActive Contributor
Hi Glenn,
All of our systems are set to update automatically, but the update is prompting users for admin. credentials.
Our users don't have admin. rights. Is there a way to run this update programmatically?
- SOSCOMP2 years agoNew Contributor
Hi we are having same issue and with our endpoint security and LMI. We have ran the LMI update today (version.15410 installed) and rebooted. Our ENDpoint product is upto date as well.
"A potentially unsafe application (Win64/LogMeIn.A) found in a file (the filename is random)" tried to access."
Please help-pop-ups occurring often!
- GlennD2 years agoGoTo Manager
Hi,
We have begun deploying the update to accounts and systems will begin auto updating over the coming days.
- lmiuser122 years agoNew Contributor
thanks for the update
- ProCentPM2 years agoGoTo Contributor
Folks,
FYI: A fix is on its way. It will be released on the 12th of March.
- alfarom2562 years agoVisitor
Thanks for the update.