Beveiligingsadvies

CVE-2024-9150

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-21 11:40:00
Laatst bijgewerkt 2025-02-21 13:14:07
Toegewezen door CERT-PL
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a host system with applications high privileges. This issue has been fixed in version 8.0.00204.0