Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-29645


Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.


Published

2021-10-12T19:15:07.677

Last Modified

2024-11-21T06:01:33.630

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachi it_operations_director ≤ 02-50-07 Yes
Application hitachi it_operations_director ≤ 03-00-12 Yes
Application hitachi it_operations_director ≤ 04-00-17 Yes
Application hitachi it_operations_director ≤ 04-50-16 Yes
Application hitachi job_management_partner_1\/it_desktop_management-manager ≤ 09-50-03 Yes
Application hitachi job_management_partner_1\/it_desktop_management-manager ≤ 10-01-06 Yes
Application hitachi job_management_partner_1\/it_desktop_management-manager ≤ 10-10-16 Yes
Application hitachi job_management_partner_1\/it_desktop_management_2-manager ≤ 10-50-11 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 08-00-04 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 08-10-05 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 08-51-18 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 09-00-07 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 09-50-09 Yes
Application hitachi job_management_partner_1\/remote_control_agent ≤ 09-51-15 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 08-00-05 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 08-10-06 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 08-51-19 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 09-00-09 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 09-50-09 Yes
Application hitachi job_management_partner_1\/software_distribution_client ≤ 09-51-13 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 08-00-07 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 08-10-06 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 08-51-19 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 09-00-09 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 09-50-09 Yes
Application hitachi job_management_partner_1\/software_distribution_manager ≤ 09-51-13 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 09-50-03 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 09-51-05 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 10-00-02 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 10-01-05 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 10-02-05 Yes
Application hitachi jp1\/it_desktop_management-manager ≤ 10-10-16 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 10-50-12 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 11-00-11 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 11-01-12 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 11-10-10 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 11-50-08 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 11-51-10 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 12-00-09 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 12-10-07 Yes
Application hitachi jp1\/it_desktop_management_2-manager ≤ 12-50-03 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 11-01-12 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 11-10-10 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 11-50-08 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 11-51-10 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 12-00-09 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 12-10-07 Yes
Application hitachi jp1\/it_desktop_management_2-operations_director ≤ 12-50-03 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-00-09 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-01-04 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-02-07 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-10-13 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-11-17 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-12-03 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-50-08 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-51-17 Yes
Application hitachi jp1\/netm\/dm_client ≤ 08-52-22 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-00-14 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-01-14 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-10-15 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-12-16 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-50-20 Yes
Application hitachi jp1\/netm\/dm_client ≤ 09-51-14 Yes
Application hitachi jp1\/netm\/dm_client ≤ 10-10-23 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-00-06 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-01-03 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-02-04 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-10-10 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-11-06 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-50-04 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 08-51-14 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 09-00-13 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 09-01-12 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 09-10-13 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 09-50-19 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 09-51-08 Yes
Application hitachi jp1\/netm\/dm_client-remote_control_feature ≤ 10-10-20 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-00-09 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-02-07 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-10-13 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-11-17 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-50-08 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-51-18 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 08-52-22 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-00-14 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-01-14 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-10-15 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-12-15 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-50-20 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 09-51-14 Yes
Application hitachi jp1\/netm\/dm_manager ≤ 10-10-24 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-00-06 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-01-03 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-02-04 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-10-10 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-11-06 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-50-04 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 08-51-14 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 09-00-13 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 09-01-12 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 09-50-20 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 09-51-08 Yes
Application hitachi jp1\/netm\/remote_control_feature ≤ 10-10-20 Yes
Application hitachi jp1\/remote_control_feature ≤ 11-00-02 Yes
Application hitachi jp1\/remote_control_feature ≤ 12-00-011 Yes
Operating System microsoft windows - No

References