CVE-2021-20793
HIGHSony Audio USB Driver <V1.10 - Privilege Escalation
Title source: llmDescription
Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
References (4)
Scores
CVSS v3
7.8
EPSS
0.0021
EPSS Percentile
42.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (2)
sony/audio_usb_driver
< 1.10
sony/hap_music_transfer
< 1.3.0
Timeline
Published
Aug 26, 2021
Tracked Since
Feb 18, 2026