Lucene search

K
cveJpcertCVE-2021-20674
HistoryMar 12, 2021 - 2:15 a.m.

CVE-2021-20674

2021-03-1202:15:13
CWE-427
jpcert
web.nvd.nist.gov
63
2
cve-2021-20674
vulnerability
untrusted search path
magicconnect client
privilege escalation
remote desktop

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

36.4%

Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified directory and to execute arbitrary code with the privilege of the user invoking the installer when a terminal is connected remotely using Remote desktop.

Affected configurations

Nvd
Node
ntt-txmagicconnectRange<2021-03-01
VendorProductVersionCPE
ntt-txmagicconnect*cpe:2.3:a:ntt-tx:magicconnect:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Installer of MagicConnect Client program",
    "vendor": "NTT TechnoCross Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "distributed before 2021 March 1"
      }
    ]
  }
]

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

36.4%

Related for CVE-2021-20674