PT-2022-16584 · Acer · Acer Quickaccess
Doit_Man
·
Published
2022-03-08
·
Updated
2022-03-16
·
CVE-2022-24286
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Acer QuickAccess versions 2.01.300x through 2.01.3029
Acer QuickAccess versions 3.00.30xx through 3.00.3037
Description
The issue concerns a local privilege escalation. It involves a user process communicating with a system authority service through a named pipe, where the named pipe has read and write rights for general users. The service program fails to verify the user during communication, allowing a thread to exist with a specific command. When the path of the program to be executed is sent, it results in local privilege escalation, where the service program executes the path with system privileges.
Recommendations
For Acer QuickAccess versions 2.01.300x through 2.01.3029, update to version 2.01.3030 or later.
For Acer QuickAccess versions 3.00.30xx through 3.00.3037, update to version 3.00.3038 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acer Quickaccess