Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a repair operation on the product.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Automation_builder | Abb | 1.1.0 (including) | 2.5.0 (including) |
| Drive_composer | Abb | 2.0 (including) | 2.7.1 (excluding) |
| Mint_workbench | Abb | * | 5866 (including) |