Remote Code Execution Vulnerability in Barco WePresent Presentation System
CVE-2021-35482

7.8HIGH

Key Information:

Vendor

Barco

Vendor
CVE Published:
21 July 2021

What is CVE-2021-35482?

A local network vulnerability in Barco MirrorOp Windows Sender prior to version 2.5.4.70 allows an attacker to execute arbitrary code on connected devices. This exploit takes advantage of the communication between systems attempting to interface with Barco’s WePresent presentation system. Once compromised, the attacker can achieve execution with the privileges of the local user, potentially leading to unauthorized access and manipulation of sensitive information.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.