PT-2021-16762 · Teradici · Teradici Pcoip Standard Agent

Published

2021-07-21

·

Updated

2022-06-06

·

CVE-2021-25698

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Teradici PCoIP Standard Agent versions prior to 21.07.0
Description The issue arises from the OpenSSL component being compiled without the no-autoload-config option. This allows an attacker to elevate privileges to those of the running process by placing a specially crafted dll in a build configuration directory.
Recommendations For versions prior to 21.07.0, update to version 21.07.0 or later to resolve the issue. As a temporary workaround, consider restricting access to build configuration directories to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25698

Affected Products

Teradici Pcoip Standard Agent