Abstract Advisory Information
The FTP module, which is not installed by default, is prone to a DLL hijacking attack allowing a standard user account to execute command with the highest privileges as NT AUTHORITYSYSTEM
Author: Dominique Righetto
Version affected
Name: Allegro Windows
Versions: 3.3.4152.0 and underCommon Vulnerability Scoring System
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Patches
Allegro Windows version 3.3.4156.1
References
- https://www.allegro.be/fr/windows
- PATCH : https://www.allegro.be/fr/windows/support
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42110
Vulnerability Disclosure Timeline
- 19/08/2021: Vulnerability discovery
- 19/08/2021: Vulnerability Report to CERT-XLM
- 08/10/2021: Vulnerability Report to Vendor
- 13/10/2021: Call with the vendor to clarify fix solutions + given PoC video
- 08/10/2021: Request CVE IDs to Mitre
- 08/10/2021: CVE IDs assigned Use CVE-2021-42110
- 12/10/2021: Call with the vendor to discuss the possible fix solutions
- 29/11/2021: Expected Vulnerability disclosure