CVE-2021-29645
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.
Affected (105)
Products: Hitachi: It Operations Director, Job Management Partner 1/it Desktop Management Manager, Job Management Partner 1/it Desktop Management 2 Manager, Job Management Partner 1/remote Control Agent, Job Management Partner 1/software Distribution Client, Job Management Partner 1/software Distribution Manager, Jp1/it Desktop Management Manager, Jp1/it Desktop Management 2 Manager, Jp1/it Desktop Management 2 Operations Director, Jp1/netm/dm Client, Jp1/netm/dm Client Remote Control Feature, Jp1/netm/dm Manager, Jp1/netm/remote Control Feature, Jp1/remote Control Feature
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 02-50 to 02-50-07 | |
| From 09-50 to 09-50-03 | |
| From 10-50 to 10-50-11 | |
| From 08-00 to 08-00-04 | |
| From 08-00 to 08-00-05 | |
| From 08-00 to 08-00-07 | |
| From 09-50 to 09-50-03 | |
| From 10-50 to 10-50-12 | |
| From 11-01 to 11-01-12 | |
| From 08-00 to 08-00-09 | |
| From 08-00 to 08-00-06 | |
| From 08-00 to 08-00-09 | |
| From 08-00 to 08-00-06 | |
| From 11-00 to 11-00-02 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.