Impact
This vulnerability allows an attacker to supply malicious code through an abandoned auto‑update domain used by OZOLS ERP. The application downloads executable scripts without performing an integrity check, then runs them with the SQL Server Agent using ActiveScripting. The result is unchecked inclusion of untrusted functionality and cleartext transmission of sensitive data. An attacker who can influence the auto‑update channel can execute arbitrary code on the host, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Ozols Grupa’s OZOLS ERP product, running on Windows, is vulnerable for all versions before 1.1.1233. The affected components are the automatic update channel – the OzolsSQL client update path, the database server job named <db>_update that uses ActiveScripting, and the serv_update.vbs script.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. While an EPSS score is not available, the absence of a KEV listing does not lower the risk; the high severity and the fact that the flaw enables remote code execution through a network‑visible update path mean that exploitation is likely if an attacker can host or redirect updates. The attack vector is inferred to be remote network access to the abandoned update domain, which the application contacts without authentication or integrity validation.
OpenCVE Enrichment