Impact
QND suffers from an improper access control flaw in a named pipe that lets a local attacker with an active Windows session run arbitrary commands with SYSTEM privileges. This is a classic local privilege escalation scenario rooted in CWE‑782. The attacker can gain full control of the machine and compromise all applications run on that system.
Affected Systems
Affected products are QualitySoft Corporation QND Advance, QND Premium and QND Standard. Specific affected versions were not supplied in the listed product families is potentially vulnerable unless a later release has been applied.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. The suggests a low‑to‑moderate current exploitation probability, and the vulnerability is not yet listed in CISA KEV. Attackers would require local access to the machine and rely on the named pipe mechanism; however, because the attacker can elevate privileges to SYSTEM, the impact is significant and the potential for widespread damage is high.
OpenCVE Enrichment