An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://myconnectionserver.visualware.com/download.html | product vendor advisory |
https://myconnectionserver.visualware.com/support/newrelease.html | release notes vendor advisory |
http://seclists.org/fulldisclosure/2021/Feb/81 | third party advisory mailing list |
http://packetstormsecurity.com/files/161571/VisualWare-MyConnection-Server-11.x-Remote-Code-Execution.html | vdb entry third party advisory |
https://www.securifera.com/advisories/cve-2021-27198/ | third party advisory |