PT-2021-18134 · Unknown · Erlang/Otp

Tim Morgan

·

Published

2021-04-09

·

Updated

2021-04-20

·

CVE-2021-29221

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Erlang/OTP versions prior to 23.2.3
Description: A local privilege escalation issue was discovered. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service running with "erlsrv.exe" to execute arbitrary code as Local System. This can occur only under specific conditions on Windows with unsafe filesystem permissions.
Recommendations: For versions prior to 23.2.3, update to version 23.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Erlang installation directory to prevent unauthorized file additions. Additionally, ensure safe filesystem permissions are in place to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29221

Affected Products

Erlang/Otp