VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.
2022-03-23T20:15:10.840
2024-11-21T06:47:40.390
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | carbon_black_app_control | < 8.5.14 | Yes |
Application | vmware | carbon_black_app_control | < 8.6.6 | Yes |
Application | vmware | carbon_black_app_control | < 8.7.4 | Yes |
Application | vmware | carbon_black_app_control | < 8.8.2 | Yes |
Operating System | microsoft | windows | - | No |