Utimaco has been made aware of a vulnerability affecting the Windows installations of some of our products.
This vulnerability could allow for an attacker to escalate Windows privileges from a standard “Authenticated User” to that of an Administrator or SYSTEM. The firmware of your Hardware Security Modules is not affected though.
Please consult the linked advisory for the details of this vulnerability, and check whether you are affected. We have published an updated SecurityServer product CD and a patch in our support portal under Support -> Downloads. Login to the support portal is required.
Download Security Advisory Document
Download HotFix Patch
This issue has been reserved in the Common Vulnerabilities and Exposures list as CVE-2020-26155. It will be published end of January 2021. Do not disclose this vulnerability before its publication on the CVE website to give all affected customers due time for fixing their installations.