Vulnerability Description
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blueplanet-Works | Appguard | < 6.7.100.1 |
Related Weaknesses (CWE)
References
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022Third Party Advisory
- https://www.beyondtrust.com/blogNot Applicable
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022Third Party Advisory
- https://www.beyondtrust.com/blogNot Applicable
FAQ
What is CVE-2021-42255?
CVE-2021-42255 is a vulnerability with a CVSS score of 7.8 (HIGH). AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory...
How severe is CVE-2021-42255?
CVE-2021-42255 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42255?
Check the references section above for vendor advisories and patch information. Affected products include: Blueplanet-Works Appguard.