Vulnerability Description
An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bopsoft | Listary | <= 6 |
Related Weaknesses (CWE)
References
- https://medium.com/%40tomerp_77017/exploiting-listary-searching-your-way-to-syst
- https://www.listary.com/downloadVendor Advisory
- https://medium.com/%40tomerp_77017/exploiting-listary-searching-your-way-to-syst
- https://www.listary.com/downloadVendor Advisory
FAQ
What is CVE-2021-41066?
CVE-2021-41066 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will...
How severe is CVE-2021-41066?
CVE-2021-41066 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41066?
Check the references section above for vendor advisories and patch information. Affected products include: Bopsoft Listary.