Improper Access Control Vulnerability in GenericSSOService Allows Local Attackers to Execute Protected Activity with System Privilege via Untrusted Applications

Improper Access Control Vulnerability in GenericSSOService Allows Local Attackers to Execute Protected Activity with System Privilege via Untrusted Applications

CVE-2021-25412 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

Learn more about our Web Application Penetration Testing UK.