Security Advisories

CVE-2021-44750: Arbitrary Code Execution

Description

F-Secure Support Tool (fsdiag) embedded within various F-Secure products for Microsoft Windows can be abused to execute arbitrary commands on the system.

STATUS: Fixed

ACTION REQUIRED: F-Secure Business Suite administrator need to apply the hotfix manually. All other products are automatically updated.

RISK LEVEL: Medium

FIX: In all other environments fix has been published through the automatic update channel.  

Affected Products

  • F-Secure FREEDOME VPN
  • F-Secure SAFE
  • F-Secure KEY
  • F-Secure Internet Security / Anti-Virus

Platforms

  • All supported Windows version for the affected product

More Information

An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.

This issue was reported to F-Secure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.

Mitigating factors

User interaction is required prior to exploitation.

Administrative privileges is required to run arbitrary scripts/commands in the system.

Credits

F-Secure Corporation would like to thanks Nasreddine Bencherchali (@nas_bench) for bringing this issue to our attention.

Date Issued: 09-Mar-2022