Vulnerability Details CVE-2021-32961
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-32961
-
cpe:2.3:a:auvesy-mdt:autosave:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:5.00