VYPR
Unrated severityNVD Advisory· Published Aug 6, 2021· Updated Aug 4, 2024

CVE-2021-35312

CVE-2021-35312

Description

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local privilege escalation in Amica Prodigy v1.7 via weak permissions on RemoteBackup.Service.exe, allowing replacement by malicious executable.

Vulnerability

The Amica Prodigy software version 1.7, part of the CIR 2000 / Gestionale Amica suite, contains a privilege escalation vulnerability in the RemoteBackup.Service.exe executable. The executable has incorrect file permissions, allowing any local unprivileged user to overwrite it. This enables replacement with a malicious binary that will be executed with LocalSystem privileges [1].

Exploitation

An attacker with local access to the system and low privileges can replace the legitimate RemoteBackup.Service.exe with a crafted malicious executable. No additional authentication or user interaction is required beyond local file write permissions. The next time the service runs, the malicious binary executes in the context of LocalSystem [1].

Impact

Successful exploitation results in local privilege escalation from an unprivileged user to LocalSystem, granting full control over the affected system. The attacker can then perform any action, including installing programs, accessing sensitive data, and creating new accounts with full rights.

Mitigation

As of the publication date (2021-08-06), no official patch was available. The vendor has not released a fix. The only workaround is to manually secure the permissions on RemoteBackup.Service.exe to prevent modification by unprivileged users, or to remove the service if not needed [1].

References
  1. Packet Storm

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.