CVE-2024-22042
HIGHSiemens Unicam FX - Local Privilege Escalation via Windows Installer Agent
Title source: llmDescription
A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYSTEM privileges. This could be exploited by an attacker to perform a local privilege escalation attack.
References (1)
Core 1
Core References
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-543502.html
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-648
Status
published
Products (1)
siemens/unicam_fx
Published
Feb 13, 2024
Tracked Since
Feb 18, 2026