Local Privilege Escalation in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42972

7.8HIGH

Summary

A vulnerability exists in Schneider Electric's Easy UPS Online Monitoring Software that allows a local attacker to perform local privilege escalation. By modifying the webroot directory, an attacker can gain elevated privileges, potentially compromising critical resources on the system. This affects several versions of the software across multiple Windows operating systems, underscoring the importance of maintaining updated software versions to mitigate such risks.

Affected Version(s)

APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022

APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022

Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.