Abstract Advisory Information


The FTP module, which is not installed by default, is prone to a DLL hijacking attack allowing a standard user account to execute command with the highest privileges as NT AUTHORITYSYSTEM

Author: Dominique Righetto

Version affected


Name: Allegro Windows

Versions: 3.3.4152.0 and under

Common Vulnerability Scoring System


7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Patches


Allegro Windows version 3.3.4156.1

References


Vulnerability Disclosure Timeline


  • 19/08/2021: Vulnerability discovery
  • 19/08/2021: Vulnerability Report to CERT-XLM
  • 08/10/2021: Vulnerability Report to Vendor
  • 13/10/2021: Call with the vendor to clarify fix solutions + given PoC video
  • 08/10/2021: Request CVE IDs to Mitre
  • 08/10/2021: CVE IDs assigned Use CVE-2021-42110
  • 12/10/2021: Call with the vendor to discuss the possible fix solutions
  • 29/11/2021: Expected Vulnerability disclosure