PT-2026-78641 · Ozols Grupa · Ozols
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ozols Grupa OZOLS versions prior to 1.1.1233
Description
The software contains a flaw in its automatic update channel, specifically affecting the OzolsSQL client update path, the
serv update.vbs file, and the <db> update SQL Server Agent job using the ActiveScripting subsystem. The issue allows the download of code without integrity checks from an untrusted control sphere and the transmission of sensitive information in cleartext due to an abandoned auto-update domain. This can lead to remote code execution (RCE) via the injection of untrusted updates on Windows systems.Recommendations
Update Ozols Grupa OZOLS to version 1.1.1233 or later.
As a temporary mitigation, isolate the system running the software to prevent unauthorized network access.
Exploit
Fix
RCE
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ozols