#VU54638 Arbitrary file upload in MDT AutoSave and AutoSave for System Platform (A4SP) - CVE-2021-32961
Published: July 9, 2021
MDT AutoSave
AutoSave for System Platform (A4SP)
MDT Software
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the getfile function. A remote attacker can execute an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.