CVE-2021-1492 Information
Description
The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful an attacker can manipulate files used by Duo Authentication Proxy installer cause Denial of Service (DoS) by deleting file(s) or replace system files to potentially achieve elevation of privileges. This is only exploitable during new installations while the installer is running and is not exploitable once installation has finished. Versions 5.2.1 of Duo Authentication Proxy installer addresses this issue.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Reference
https://help.duo.com/s/article/6789
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.1
Share on: