First published: Wed Mar 09 2022(Updated: )
An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure Client Security | ||
F-secure Countercept | ||
F-secure Elements | ||
F-secure Email And Server Security | ||
F-Secure Server Security | ||
Microsoft Windows |
MITIGATION FACTOR User interaction is required prior to exploitation. Administrative privileges is required to run arbitrary commands in the system.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44750 is an arbitrary code execution vulnerability found in the F-Secure Support Tool.
A standard user can create a special configuration file that, when executed by an administrator, can run any commands.
F-Secure Client Security, F-Secure Countercept, F-Secure Elements, F-Secure Email And Server Security, and F-Secure Server Security are affected by CVE-2021-44750.
CVE-2021-44750 has a severity rating of 7.3 (High).
Apply the necessary updates and patches provided by F-Secure to mitigate CVE-2021-44750.