The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program execution within the vHub driver.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Link | Tags |
---|---|
https://advisory.teradici.com/security-advisories/100/ | vendor advisory |