VYPR
Unrated severityNVD Advisory· Published Apr 1, 2022· Updated Apr 16, 2025

MDT AutoSave Unrestricted Upload of File with Dangerous Type

CVE-2021-32961

Description

A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.