Back to Database
Status published
Medium
CVE-2014-8494
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for...
Vulnerability Description
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8494
Credits & Attribution
No credits recorded in the NVD database.
References
More from estsoft
View All →CVE-2018-10027
ESTsoft ALZip before 10.76 allows local users to execute arbitrary...
High
7.8
CVE-2017-11323
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows...
High
7.8
CVE-2012-0315
Untrusted search path vulnerability in ALFTP before 5.31 allows local...
Critical
9.3
CVE-2011-1336
Buffer overflow in ALZip 8.21 and earlier allows remote attackers...
Critical
9.3
CVE-2010-5211
Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users...
Medium
6.9
Affected Vendor
estsoft
View all reports →Affected Software
alupdate
Vulnerable Versions:
8.5.1.0.0
Timeline
Official Publish:
November 3rd, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.