A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-189-02 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-04-01T22:17:08
Updated: 2024-08-03T23:33:56.379Z
Reserved: 2021-05-13T00:00:00
Link: CVE-2021-32957
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-04-01T23:15:09.757
Modified: 2024-11-21T06:08:00.263
Link: CVE-2021-32957
Redhat
No data.