Vulnerability Description
Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable file via an alternative data stream.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ysoft | Safeq | 6.0.55 |
Related Weaknesses (CWE)
References
- https://www.ysoft.com/enVendor Advisory
- https://www.ysoft.com/en/legal/ysoft-safeq-flexispoolerVendor Advisory
- https://www.ysoft.com/enVendor Advisory
- https://www.ysoft.com/en/legal/ysoft-safeq-flexispoolerVendor Advisory
FAQ
What is CVE-2021-31859?
CVE-2021-31859 is a vulnerability with a CVSS score of 7.8 (HIGH). Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable file via an alternative data stream.
How severe is CVE-2021-31859?
CVE-2021-31859 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31859?
Check the references section above for vendor advisories and patch information. Affected products include: Ysoft Safeq.