Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://jungo.com/windriver/versions/ | release notes |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf | third party advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 | third party advisory us government resource |