QID 378005

Date Published: 2023-03-01

QID 378005: Fujitsu PlugFree Network Privilege Escalation Vulnerability

Plugfree Network is the wireless communications software. The program is designed to help manage the user's wireless connection's and built in wireless network adaptor.

Affected Versions:
Plugfree Network v7.3.0.3 and earlier

QID Detection Logic (Authenticated)
The detection checks for vulnerable File Version of Plugfree Network.

An Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to download the patch version or later from Fujitsu Downloads to fix the vulnerability.

    Vendor References

    CVEs related to QID 378005

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-27089 URL Logo hansesecure.de/2022/03/schwachstelle-in-fujitsu-plugfree-network/