4.6
CVSSv2

CVE-2021-29645

Published: 12/10/2021 Updated: 12/07/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hitachi job_management_partner_1\\/remote_control_agent

hitachi it_operations_director

hitachi job_management_partner_1\\/it_desktop_management-manager

hitachi job_management_partner_1\\/software_distribution_client

hitachi job_management_partner_1\\/software_distribution_manager

hitachi jp1\\/it_desktop_management_2-operations_director

hitachi job_management_partner_1\\/it_desktop_management_2-manager

hitachi jp1\\/it_desktop_management-manager

hitachi jp1\\/it_desktop_management_2-manager

hitachi jp1\\/netm\\/dm_client

hitachi jp1\\/netm\\/dm_manager

hitachi jp1\\/netm\\/dm_client-remote_control_feature

hitachi jp1\\/netm\\/remote_control_feature

hitachi jp1\\/remote_control_feature