Delete Vulnerability in BlackBerry Protect for Windows by BlackBerry
CVE-2021-32022

5.5MEDIUM

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
10 November 2021

What is CVE-2021-32022?

A low privileged delete vulnerability exists in the CEF RPC server of BlackBerry Protect for Windows, where versions up to 1574 may be susceptible. An attacker could exploit this flaw to execute code within the context of a BlackBerry Cylance service possessing administrative rights on the system. This exploit could potentially allow the attacker to delete data from the local system, posing a significant risk to data integrity and security.

Affected Version(s)

BlackBerry Protect for Windows Version 1574 and earlier

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.