First published: Fri Jan 28 2022(Updated: )
A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech SQ Manager | =1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40388 is a privilege escalation vulnerability that exists in Advantech SQ Manager Server 1.0.6.
CVE-2021-40388 can be exploited by providing a specially-crafted file, which can be replaced in the system to escalate privileges to NT SYSTEM authority.
The vulnerability affects Advantech SQ Manager Server 1.0.6.
CVE-2021-40388 has a severity score of 8.8 (high).
To fix CVE-2021-40388, it is recommended to apply the latest security patches provided by Advantech or upgrade to a non-vulnerable version of Advantech SQ Manager Server.