CVE-2021-41065
Last modified
CVE-2021-41065 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to duplicate the victim's token to impersonate him. This exploit is valid in certain Windows versions (Microsoft has patched the issue in later Windows 10 builds).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bopsoft | Listary | <= 6 |
References
- https://www.listary.com/downloadVendor Advisory
- https://www.listary.com/downloadVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41065?
How severe is CVE-2021-41065?
How do I fix CVE-2021-41065?
Are you affected by CVE-2021-41065?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
