PT-2021-15313 · F5 · Edge Client
Published
2021-02-12
·
Updated
2021-02-19
·
CVE-2021-22980
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Edge Client versions 7.1.x through 7.1.8.5
Edge Client versions 7.1.9.x through 7.1.9.8
Edge Client versions 7.2.x through 7.2.1.1
Description
An untrusted search path issue in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. This requires user interaction, where the victim must run the utility on the Windows system.
Recommendations
For Edge Client versions 7.1.x through 7.1.8.5, update to version 7.1.8.5 or later.
For Edge Client versions 7.1.9.x through 7.1.9.8, update to version 7.1.9.8 or later.
For Edge Client versions 7.2.x through 7.2.1.1, update to version 7.2.1.1 or later.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge Client