CVE-2021-42110: High severity allegro vulnerability
Published Dec 8, 2021
·Updated
An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.
Affected Software
1 affected component
Allegro Allegro WIndows<3.3.4156.1
Remediation
Event History
Dec 8, 2021
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42110?
The severity of CVE-2021-42110 is high with a CVSS score of 7.8.
2
How can a standard user escalate privileges to SYSTEM with CVE-2021-42110?
A standard user can escalate privileges to SYSTEM if the FTP module is installed, due to DLL hijacking.
3
Which version of Allegro Windows is affected by CVE-2021-42110?
Allegro Windows version up to 3.3.4156.1 is affected by CVE-2021-42110.
4
How can I fix CVE-2021-42110?
To fix CVE-2021-42110, update to a version of Allegro Windows that is later than 3.3.4156.1.
5
Where can I find more information about CVE-2021-42110?
More information about CVE-2021-42110 can be found at the following references: http://www.popsy.com/Documents/Setups/Setup.Allegro.3.3.4154.2.exe, https://excellium-services.com/cert-xlm-advisory/CVE-2021-42110