PT-2026-97806 · Hfs2 · Hfs2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HFS2 versions 2.4.0 and earlier
Description
An unauthenticated arbitrary file access issue exists due to a lack of an authorization model in the macro dispatcher and a failure in the path resolver to confine absolute paths. This allows unauthenticated attackers to read, write, append, and delete files across any directory accessible by the HFS service account, extending beyond the intended shared folder. By manipulating the template engine, an attacker can compromise the confidentiality, integrity, and availability of the host system.
Recommendations
Update HFS2 to a version later than 2.4.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hfs2