CVE-2021-20793

Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sony:audio_usb_driver:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:sony:hap_music_transfer:*:*:*:*:*:*:*:*

History

01 Sep 2021, 21:23

Type Values Removed Values Added
CWE CWE-427
CVSS v2 : unknown
v3 : unknown
v2 : 4.4
v3 : 7.8
CPE cpe:2.3:a:sony:audio_usb_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:sony:hap_music_transfer:*:*:*:*:*:*:*:*
References (MISC) https://www.sony.co.uk/electronics/support/software/00266758 - (MISC) https://www.sony.co.uk/electronics/support/software/00266758 - Product, Vendor Advisory
References (MISC) https://jvn.jp/en/jp/JVN80288258/index.html - (MISC) https://jvn.jp/en/jp/JVN80288258/index.html - Third Party Advisory
References (MISC) https://www.sony.co.uk/electronics/support/software/00266642 - (MISC) https://www.sony.co.uk/electronics/support/software/00266642 - Product, Vendor Advisory
References (MISC) https://www.sony.co.uk/electronics/support/software/00266749 - (MISC) https://www.sony.co.uk/electronics/support/software/00266749 - Product, Vendor Advisory

26 Aug 2021, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-26 02:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-20793

Mitre link : CVE-2021-20793

CVE.ORG link : CVE-2021-20793


JSON object : View

Products Affected

sony

  • audio_usb_driver
  • hap_music_transfer
CWE
CWE-427

Uncontrolled Search Path Element