Heimdalsecurity develops a focused line of endpoint security and threat-detection products, including Thor and its Heimdal suite, that operate across enterprise environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in weakness classes tied to input validation, certificate handling, permission management, and regular-expression complexity—flaws that can undermine authentication boundaries and grant unintended system access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Heimdalsecurity over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8351CRITICAL Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a | Mar 21, 2019 | 9.1 | 28 | NO | NO |
CVE-2022-24618HIGH Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the | Mar 10, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-29486CRITICAL An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sen | Dec 21, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-29485CRITICAL An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary co | Dec 21, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-29487CRITICAL An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat | Dec 21, 2023 | 9.1 | 24 | NO | NO |
CVE-2018-5349HIGH A vulnerability has been found in Heimdal PRO v2.2.190, but it is most likely also present in Heimdal FREE and Heimdal CORP. Faulty permissions on the directory "C:\ProgramData\Hei | Mar 22, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-5731HIGH An issue was discovered in Heimdal PRO 2.2.190. As part of the scanning feature, a process called md.hs writes an executable called CS1.tmp to C:\windows\TEMP. Afterwards the execu | Mar 22, 2018 | 7.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Heimdalsecurity.
Media articles that mention a CVE ID that affects a product developed by Heimdalsecurity — matched by CVE ID, not by vendor name.