MDT AutoSave Unrestricted Upload of File with Dangerous Type
Vulnerability Description
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32961
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Amir Preminger of Claroty Research reported these vulnerabilities to MDT Software.
More from MDT Software
View All →Affected Vendor
MDT Software
View all reports →