Description
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges.
Published:
2026-08-24
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 24 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability in Entevo HMI V2 R5 P0 M4 allows attackers to escape Kiosk Mode by opening the application manual in an external PDF viewer and abusing the Print functionality to access Windows Explorer and execute arbitrary commands with administrative privileges. | A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges. |
Mon, 24 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability in Entevo HMI V2 R5 P0 M4 allows attackers to escape Kiosk Mode by opening the application manual in an external PDF viewer and abusing the Print functionality to access Windows Explorer and execute arbitrary commands with administrative privileges. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-24T14:01:32.759Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30512
No data.
Status : Received
Published: 2026-08-24T14:16:53.453
Modified: 2026-08-24T15:16:37.823
Link: CVE-2026-30512
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.