First published: Wed Nov 10 2021(Updated: )
A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the system and gaining the ability to delete data from the local system.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
Blackberry Protect | <=1574 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-32022.
The severity of CVE-2021-32022 is medium with a severity value of 5.5.
BlackBerry Protect for Windows versions 1574 and earlier are affected by CVE-2021-32022.
CVE-2021-32022 could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the system and gain the ability to delete data.
Please refer to the official BlackBerry support article for information on how to fix CVE-2021-32022.