Link following in Apex One - CVE-2021-45231

 

Link following in Apex One - CVE-2021-45231

Published: December 29, 2021 / Updated: January 6, 2022


Vulnerability identifier: #VU59108
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45231
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure link following. A local user can create a specially crafted symbolic link and overwrite arbitrary files with arbitrary content. Successful exploitation of the vulnerability may result in execution of arbitrary code with elevated privileges.


Affected software

Apex One
Worry-Free Business Security

How to mitigate CVE-2021-45231

Install updates from vendor's website.

Apex One - update to Patch 6 B10048
Worry-Free Business Security - update to 10.0 SP1 Patch 2368

External References

Related Security Bulletins