PT-2021-20365 · Unknown · Millennium Millewin

Andrea Intilangelo

·

Published

2021-02-09

·

Updated

2021-02-11

·

CVE-2021-3394

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Millennium Millewin versions 13.39.028, 13.39.28.3342, and 13.39.146.1
Description: The issue is related to insecure folder permissions in Millennium Millewin, allowing a malicious user to perform a local privilege escalation.
Recommendations: For versions 13.39.028, 13.39.28.3342, and 13.39.146.1, consider restricting access to the insecurely permissioned folders as a temporary mitigation measure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3394

Affected Products

Millennium Millewin