Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://jungo.com/windriver/versions/ | release notes |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf | third party advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 | third party advisory us government resource |