QID 376409

Date Published: 2022-03-28

QID 376409: Abyss Web Server Secure Sockets Layer (SSL)/Transport Layer Security (TLS) Engine Vulnerability

Abyss Web Server is a freely available personal Web server. It is maintained by Aprelium Technologies and runs on Microsoft Windows as well as Linux. Abyss Web Server installs 'AbyssWebServer' service with an unquoted service path running with SYSTEM privileges which allows an authenticated, local attacker to escalate privileges. Affected Versions:
Abyss Web Server prior to version X1 2.14.2

Successful exploitation of this vulnerability allows a local attacker to potential crashes.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    There are no solutions available at this time. Check for upgrades from Aprelium's download site.
    Vendor References

    CVEs related to QID 376409

    Software Advisories
    Advisory ID Software Component Link
    Abyss Web Server URL Logo aprelium.com/news/abws2-14-2.html