Impact
CWE-269 describes a privilege escalation flaw that allows an attacker to elevate privileges within Johnson Controls victor Web for Windows. The vulnerability is referenced as capec-233, indicating that an attacker can obtain higher privileges than intended by exploiting a weakness in how the application handles user roles or access controls. The flaw exists in all pre‑7.1 releases of victor Web, enabling a threat actor who has local access to the system to gain administrative or equivalent rights, thereby compromising confidentiality, integrity, and availability of the affected environment.
Affected Systems
All installations of Johnson Controls victor Web running on Windows with a version earlier than 7.1 are affected. The product is not impacted if the system has been upgraded to 7.1 or later. No other vendor or product is listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The vulnerability is not in CISA’s KEV catalog. Based on the description, the likely attack vector is local; an attacker needs to compromise a user account or execute code on the host to take advantage of the privilege escalation flaw. Without an explicit remote exploitation path, the risk is confined to environments where local access can be achieved, highlighting the importance of secure local configurations and restricted user privileges.
OpenCVE Enrichment