PT-2021-17302 · Mdaemon · Mdaemon

Chudypb

·

Published

2021-04-14

·

Updated

2021-04-21

·

CVE-2021-27183

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MDaemon versions prior to 20.0.4
Description: An issue was discovered that allows administrators to exploit an Arbitrary File Write vulnerability using Remote Administration. This enables an attacker to create new files in any location of the filesystem or modify existing files, potentially leading to Remote Code Execution.
Recommendations: For versions prior to 20.0.4, update to version 20.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to Remote Administration to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27183

Affected Products

Mdaemon