[Security Vulnerability Alert] Simopro | WinMatrix - Missing Authentication

 
2026/4/20 ~ 2026/10/20
View Count:35

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202604-00000014

[Content Description]
【Simopro|WinMatrix - Missing Authentication】(CVE-2026-6348, CVSS: 8.8)Simopro WinMatrix agent program contains a Missing Authentication vulnerability. An attacker who has successfully authenticated on the local machine can execute arbitrary code with system privileges on the local machine and all hosts in the environment where the agent program is installed.

[Affected Platforms]
WinMatrix agent program versions 3.5.13 to 3.5.26.15

[Recommended Actions]
Please update the agent program to version 3.5.27.5 or later.

[References]
1. https://www.twcert.org.tw/tw/cp-132-10839-2d9a7-1.html

Files
system_update_alt參考資料
Top↑