Impact
QND suffers from an improper access control flaw in a named pipe that lets a local attacker with an active Windows session run arbitrary commands with SYSTEM privileges. This is a classic local privilege escalation scenario rooted in CWE-782. The attacker can gain full control of the machine and compromise all applications run on that system.
Affected Systems
The affected products are QualitySoft Corporation QND Advance, QND Premium, and QND Standard. Specific affected versions were not supplied, so any unpatched version within these families may be vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. The EPSS score is 1%, suggesting a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would require local access to the machine and would exploit the named pipe mechanism; upon success they could elevate privileges to SYSTEM, enabling full control over the system.
OpenCVE Enrichment