Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a repair operation on the product.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Automation_builder | Abb | 1.1.0 (including) | 2.5.0 (including) |
Drive_composer | Abb | 2.0 (including) | 2.7.1 (excluding) |
Mint_workbench | Abb | * | 5866 (including) |