Input validation error in Ethernet Diagnostic Driver for Windows - CVE-2021-0135
Published: November 10, 2021
Vulnerability identifier: #VU58103
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0135
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and gain elevated privileges on the target system.
Affected software
Ethernet Diagnostic Driver for Windows
SupportAssist for Business PCs
SupportAssist for Home PCs
Server Update Utility
SupportAssist for Business PCs
SupportAssist for Home PCs
Server Update Utility
How to mitigate CVE-2021-0135
Install updates from vendor's website.
Ethernet Diagnostic Driver for Windows - update to 1.4.0.10
SupportAssist for Business PCs - update to 2.4.1
SupportAssist for Home PCs - update to 3.10.0
Server Update Utility - update to 23.07.00
SupportAssist for Business PCs - update to 2.4.1
SupportAssist for Home PCs - update to 3.10.0
Server Update Utility - update to 23.07.00