CVE-2021-29645 HIGH

CVE-2021-29645

Vendor N/A
Product n/a
Published October 12, 2021
Last update August 3, 2024

CVSS base score

7.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AC:H/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N

What the vulnerability does

01Description

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

Key dates

02Disclosure timeline

October 12, 2021 CVE published
August 3, 2024 Record updated