U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
Attacker sends specially crafted malicious serialized data to the vulnerable endpoint of the U-Office Force application. The server deserializes the received data without proper validation of its content, leading to execution of malicious code embedded in it. The attack can be carried out remotely over the network without requiring any access credentials.
Attacker gains the ability to execute arbitrary code on the server (RCE), which in practice may mean complete system takeover, data theft, malicious software installation, or further lateral movement in the organization's network.
Apply patches available from the vendor according to references. Detailed information about patched versions is available at: https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html and https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html
Edetw U-Office Force — versions indicated in vendor references (TWCERT)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEdetw U Office Force
APPEdetw29.50< 29.50
Related vulnerabilities
U-Office Force: Nieautoryzowane logowanie jako administrator przez manipulację cookies
e-Excellence U-Office Force — niekontrolowany upload pliku umożliwiający RCE
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote atta...
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote atta...
The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers wit...