Vulnerability Description
In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mbconnectline | Mbdialup | <= 3.9r0.0 |
Related Weaknesses (CWE)
References
- https://cert.vde.com/de-de/advisories/vde-2021-017Third Party Advisory
- https://cert.vde.com/de-de/advisories/vde-2021-017Third Party Advisory
FAQ
What is CVE-2021-33526?
CVE-2021-33526 is a vulnerability with a CVSS score of 7.8 (HIGH). In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configur...
How severe is CVE-2021-33526?
CVE-2021-33526 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33526?
Check the references section above for vendor advisories and patch information. Affected products include: Mbconnectline Mbdialup.