Untrusted search path in RoboHelp - CVE-2021-21070

 

Untrusted search path in RoboHelp - CVE-2021-21070

Published: April 13, 2021


Vulnerability identifier: #VU52186
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21070
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the way the application handles inclusion of libraries. A local user can place a malicious file into the same directory as the file, associated with the application, trick the victim into opening it and execute arbitrary code with elevated privileges.


Affected software

RoboHelp

How to mitigate CVE-2021-21070

Install updates from vendor's website.

RoboHelp - update to 2020.0.4

External References

Related Security Bulletins