PT-2021-19498 · Splinterware · Splinterware System Scheduler Professional

Published

2021-07-06

·

Updated

2022-07-12

·

CVE-2021-31771

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Splinterware System Scheduler Professional version 5.30
Description The issue is related to insecure folders permissions, affecting where the service 'WindowsScheduler' calls its executable. This allows a non-privileged user to execute arbitrary code with elevated privileges, specifically system level privileges as "nt authoritysystem", since the service runs as Local System.
Recommendations For Splinterware System Scheduler Professional version 5.30, consider restricting access to the 'WindowsScheduler' service to minimize the risk of exploitation. As a temporary workaround, review and adjust the folder permissions to prevent non-privileged users from executing arbitrary code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-31771

Affected Products

Splinterware System Scheduler Professional