Local Privilege Escalation in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42972
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 1 February 2023
What is CVE-2022-42972?
A vulnerability exists in Schneider Electric's Easy UPS Online Monitoring Software that allows a local attacker to perform local privilege escalation. By modifying the webroot directory, an attacker can gain elevated privileges, potentially compromising critical resources on the system. This affects several versions of the software across multiple Windows operating systems, underscoring the importance of maintaining updated software versions to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022
Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved