CVE-2021-28825: TIBCO Messaging - Eclipse Mosquitto Distribution - Core Windows Platform Installation vulnerability
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition: versions 1.3.0 and below and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition: versions 1.3.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28825?
CVE-2021-28825 has been classified as a low-severity vulnerability.
How do I fix CVE-2021-28825?
To address CVE-2021-28825, update your TIBCO Messaging - Eclipse Mosquitto Distribution - Core to the latest version beyond 1.3.0.
What software is affected by CVE-2021-28825?
CVE-2021-28825 affects TIBCO Messaging - Eclipse Mosquitto Distribution - Core Community and Enterprise Editions up to version 1.3.0.
Can CVE-2021-28825 be exploited remotely?
CVE-2021-28825 does not allow for remote exploitation and requires low privileges for potential impact.
Who is responsible for fixing CVE-2021-28825?
It is the responsibility of system administrators using the affected TIBCO messaging products to apply the necessary updates for CVE-2021-28825.