Untrusted search path in otp - CVE-2021-29221

 

Untrusted search path in otp - CVE-2021-29221

Published: April 10, 2026


Vulnerability identifier: #VU125771
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29221
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to an untrusted search path in erlsrv.exe and the Erlang/OTP installation directory when adding files to an existing installation's directory on Windows with unsafe filesystem permissions. A remote attacker can add files to an existing installation's directory to escalate privileges.

User interaction is required, and the issue occurs only under specific conditions on Windows with unsafe filesystem permissions.


Affected software

otp

How to mitigate CVE-2021-29221

Install security update from vendor's website.

otp - update to 23.2.3

External References

Related Security Bulletins