A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19645 | A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:siemens:unicam_fx_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:a:siemens:unicam_fx:-:*:*:*:*:*:*:* |
| Vendors & Products |
Siemens unicam Fx Firmware
|
Mon, 21 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens unicam Fx Siemens unicam Fx Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:siemens:unicam_fx:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:unicam_fx_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens unicam Fx Siemens unicam Fx Firmware |
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-04-10T19:06:36.268Z
Reserved: 2024-01-04T13:24:07.552Z
Link: CVE-2024-22042
Updated: 2024-08-01T22:35:34.455Z
Status : Analyzed
Published: 2024-02-13T09:15:47.157
Modified: 2024-12-16T15:02:32.453
Link: CVE-2024-22042
No data.
OpenCVE Enrichment
No data.
EUVD