CVE-2026-84408
8.8
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| QualitySoft Corporation | QND Premium | 0 <= Ver.11.1i | affected |
| QualitySoft Corporation | QND Standard | 0 <= Ver.11.1i | affected |
| QualitySoft Corporation | QND Advance | 0 <= Ver.11.0.9i | affected |
Weaknesses
- CWE-782: Exposed IOCTL with insufficient access control
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.