Input validation error in Ethernet Diagnostic Driver for Windows - CVE-2021-0135

 

Input validation error in Ethernet Diagnostic Driver for Windows - CVE-2021-0135

Published: November 10, 2021


Vulnerability identifier: #VU58103
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0135
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and gain elevated privileges on the target system.


Affected software

Ethernet Diagnostic Driver for Windows
SupportAssist for Business PCs
SupportAssist for Home PCs
Server Update Utility

How to mitigate CVE-2021-0135

Install updates from vendor's website.

Ethernet Diagnostic Driver for Windows - update to 1.4.0.10
SupportAssist for Business PCs - update to 2.4.1
SupportAssist for Home PCs - update to 3.10.0
Server Update Utility - update to 23.07.00

External References

Related Security Bulletins