96% (68) 94 views 3 pages

MiCOM S1 Studio Vulnerability Disclosure

AI-enhanced description

This document discloses a vulnerability in Schneider Electric's MiCOM S1 Studio software (up to version 3.5.2), where the installer grants read/write access to executables, allowing local users to manipulate configuration files and Windows services, potentially leading to privilege escalation or misoperation of protective relays. Mitigations include using best IT practices, User Access Control (UAC), and upgrading to version 5.0.0, which resolves the issue with digital signatures, read-only privileges, and compiler security settings.

Uploaded by santiago.fischer
Download
/ 3
Loading document…