CVE-2024-12902

HIGH

ANCHOR - Privilege Escalation

Title source: llm
STIX 2.1

Description

ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these accounts use default passwords, attackers could remotely log in to the virtual machine using the default credentials.

Scores

CVSS v3 8.4
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (2)
Global Wisdom Software/ANCHOR 2.5.* - 2.5.9.5
Global Wisdom Software/ANCHOR 2.7.* - 2.7.2.4
Published Dec 23, 2024
Tracked Since Feb 18, 2026