A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.
History

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens unicam Fx
Siemens unicam Fx Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:siemens:unicam_fx:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:unicam_fx_firmware:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens unicam Fx
Siemens unicam Fx Firmware

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-02-13T09:00:06.519Z

Updated: 2024-08-01T22:35:34.455Z

Reserved: 2024-01-04T13:24:07.552Z

Link: CVE-2024-22042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-13T09:15:47.157

Modified: 2024-10-21T19:50:08.363

Link: CVE-2024-22042

cve-icon Redhat

No data.