Read Time:30 Second

A vulnerability has been discovered in Novi Survey, which could allow for arbitrary code execution. Successful exploitation of this vulnerability could allow for remote attackers to execute arbitrary code on the server in the context of the service account on affected installations of Novi Survey. Depending on the privileges associated with the service account an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

Read More