PT-2025-7455 · Unknown · Wyn Enterprise

Maksym Brzęczek

·

Published

2025-02-21

·

Updated

2025-02-21

·

CVE-2024-9150

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wyn Enterprise versions prior to 8.0.00204.0
Description The report generation functionality in Wyn Enterprise allows for code inclusion but does not sufficiently limit what code might be included. An attacker can use a low-privileges account to abuse this functionality, execute malicious code, load DLL libraries, and execute OS commands on a host system with applications' high privileges.
Recommendations For versions prior to 8.0.00204.0, update to version 8.0.00204.0 to fix the issue. As a temporary workaround, consider restricting access to the report generation functionality to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-9150

Affected Products

Wyn Enterprise