Description
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.9R0.5
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20218 | In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/de-de/advisories/vde-2021-017 |
|
History
No history.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-17T01:56:14.438Z
Reserved: 2021-05-24T00:00:00.000Z
Link: CVE-2021-33526
No data.
Status : Modified
Published: 2021-08-02T11:15:11.223
Modified: 2024-11-21T06:09:00.530
Link: CVE-2021-33526
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD