PT-2021-19498 · Splinterware · Splinterware System Scheduler Professional
Published
2021-07-06
·
Updated
2022-07-12
·
CVE-2021-31771
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Splinterware System Scheduler Professional version 5.30
Description
The issue is related to insecure folders permissions, affecting where the service 'WindowsScheduler' calls its executable. This allows a non-privileged user to execute arbitrary code with elevated privileges, specifically system level privileges as "nt authoritysystem", since the service runs as Local System.
Recommendations
For Splinterware System Scheduler Professional version 5.30, consider restricting access to the 'WindowsScheduler' service to minimize the risk of exploitation. As a temporary workaround, review and adjust the folder permissions to prevent non-privileged users from executing arbitrary code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splinterware System Scheduler Professional