First published: Fri Jan 28 2022(Updated: )
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Deviceon\/iservice | =1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40396 is a privilege escalation vulnerability in the installation of Advantech DeviceOn/iService 1.1.7.
CVE-2021-40396 has a severity value of 8.8, which is classified as high.
CVE-2021-40396 allows an attacker to replace a system file with a specially-crafted file, which escalates privileges to NT SYSTEM authority.
An attacker can provide a malicious file to trigger CVE-2021-40396 and escalate privileges on the system.
At the moment, there is no specific fix available for CVE-2021-40396. It is recommended to follow the vendor's security advisories for updates or patches.