Cyber Resilience
← All news
Confirmed2

Siemens IAM Client

Siemens fixed an unquoted-search-path flaw in IAM Client that let a logged-in local user escalate privileges. Fixes are out for several affected products; others are still pending per Siemens' own advisory. Run Siemens IAM tooling? Update now. Most shops without it can skip this one.
Sources (1)
What this means for you — CISO:Siemens IAM Client has an unquoted search path flaw allowing a local authenticated user to escalate privileges. New versions are out for several affected products; check the advisory for which ones and patch those in your environment.
What this means for you — Lean IT orgs:This is Siemens industrial software, not typical office IT — most lean shops won't run it, but if you use Siemens automation products, check whether IAM Client is part of your install and update.
What this means for you — MSP:Flag any client running Siemens industrial/automation software for this advisory — check each affected product against the CSAF list and confirm patch versions per install.
What this means for you — Researcher:Classic unquoted search path privilege escalation, authenticated local attacker only — worth checking which binaries/services are affected across the listed Siemens products and whether any expose the flaw remotely via chained access.