VYPR

Listary

by Bopsoft

CVEs (2)

  • CVE-2021-41066HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user…

  • CVE-2021-41065HigDec 14, 2021
    risk 0.47cvss 7.3epss 0.01

    An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to…