Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Allegro Windows 输入验证错误漏洞
Vulnerability Description
Allegro Windows是比利时Allegro公司的一个会计和管理解决方案。 Allegro Windows 中存在输入验证错误漏洞,该漏洞源于产品未对调用的DLL文件进行有效验证。攻击者可在安装FTP模块后引起DLL劫持将特权提升至SYSTEM。以下产品及版本受到影响:Allegro Windows 3.3.4156.1 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A