6.8
CVSSv3

CVE-2021-34546

Published: 10/06/2021 Updated: 22/06/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An unauthenticated attacker with physical access to a computer with NetSetMan Pro prior to 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netsetman netsetman

Exploits

NetSetManPro version 472 suffers from a privilege escalation vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> secuvera-SA-2021-01: Privilege Escalation in NetSetMan Pro 472 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...