CVE-2021-32957
Summary
| CVE | CVE-2021-32957 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-01 23:15:00 UTC |
| Updated | 2022-04-11 17:19:00 UTC |
| Description | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Auvesy-mdt | Autosave | All | All | All | All |
| Application | Auvesy-mdt | Autosave | All | All | All | All |
| Application | Auvesy-mdt | Autosave For System Platform | All | All | All | All |
| Application | Auvesy-mdt | Autosave For System Platform | 5.00 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MDT AutoSave | CISA | CONFIRM | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Amir Preminger of Claroty Research reported these vulnerabilities to MDT Software.
There are currently no legacy QID mappings associated with this CVE.