Local Attacker Can Execute Malicious Code with Administrative Privileges via Unsafe Reflection in ICONICS GENESIS64
CVE-2024-1574

6.7MEDIUM

Key Information:

Vendor

Iconics

Vendor
CVE Published:
4 July 2024

What is CVE-2024-1574?

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing feature of ICONICS GENESIS64 versions 10.97 to 10.97.2, Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.2 and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code with administrative privileges by tampering with a specific file that is not protected by the system.

Affected Version(s)

GENESIS64 versions 10.97 to 10.97.2

GENESIS64 versions 10.97 to 10.97.2

MC Works64 all versions

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.