CVE Published: 02/08/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: CERTVDE |
Vendor: MB connect line |
Product: mbDIALUP Status : PUBLISHED
CVE-2021-33526 Description
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H