Local Privilege Escalation via Symbolic Link in Mitsubishi Electric GENESIS64 and MC Works64
Execution with Unnecessary Privileges vulnerability in the Pager agent of multi-agent notification feature in Mitsubishi Electric Iconics Digital Solutions GENESIS64 before 10.97.3, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated malicious user to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the services of the affected products to a target file. This could allow the malicious user to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mitsubishi electric corporation genesis64 |
||
mitsubishi electric corporation mc works64 |
||
mitsubishi electric iconics digital solutions genesis64 |