Execution with Unnecessary Privileges vulnerability in the Pager agent of multi-agent notification feature in Mitsubishi Electric Iconics Digital Solutions GENESIS64 prior to 10.97.3, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the services of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.
References
Configurations
No configuration.
History
29 May 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 May 2025, 14:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 May 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-15 23:15
Updated : 2025-05-29 05:15
NVD link : CVE-2025-0921
Mitre link : CVE-2025-0921
CVE.ORG link : CVE-2025-0921
JSON object : View
Products Affected
No product.
CWE
CWE-250
Execution with Unnecessary Privileges