CVE-2026-20517: Use After Free
In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10900510
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The attacker must already have System privilege. The issue is described as a local escalation of privilege condition.
Is user interaction required?
No. Exploitation does not require user interaction.
What should be done if remediation is needed?
Track and apply the vendor remediation identified as Patch ID ALPS10900510 and Issue ID MSV-6781. No temporary workaround or configuration-based mitigation is provided in the available data.
Which versions are affected?
The available data does not specify affected or fixed version ranges. Validate exposure against the vendor bulletin and patch tracking information for ALPS10900510.