Link following in Apex One - CVE-2021-45231
Published: December 29, 2021 / Updated: January 6, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following. A local user
can create a specially crafted symbolic link and overwrite arbitrary
files with arbitrary content. Successful exploitation of the vulnerability may result in execution of arbitrary code with elevated privileges.
Affected software
Worry-Free Business Security
How to mitigate CVE-2021-45231
Worry-Free Business Security - update to 10.0 SP1 Patch 2368