Horizon Alert
Summary of the vulnerability and why it matters
A security flaw in the Altium Enterprise Server Collaboration Service could allow an authenticated user to access sensitive server files, including administrator credentials, potentially leading to full control of the system. This issue does not affect Altium 365 cloud deployments.
- Flaw lets authenticated users steal server credentials.
- Critical access grants full server control.
- Confirm if on-premises server is affected.
Attack Path
How an attacker could exploit the issue
An authenticated user can exploit this vulnerability by sending a specially crafted filename within a collaboration message. The server improperly processes this filename when constructing download paths for MCAD and Simulation files. This allows an attacker to read sensitive files from the server's filesystem, including configuration files that contain privileged account credentials, potentially granting administrative access and full server control.
- Authenticated user, network access.
- Crafting filenames in download requests.
- Full administrative control of server.
Live Threat
Current exploitation, exposure, and threat context
A path traversal vulnerability in Altium Enterprise Server's file download feature could allow authenticated users to read arbitrary files from the server. This is possible when a specially crafted filename is submitted in a collaboration message, leading to unvalidated path construction for file downloads. If the vulnerable server configuration is accessible externally and the master configuration file is targeted, an attacker could potentially gain administrative control of the server.
- Server configuration and credentials.
- Crafted filename in download requests.
- Full server control could be achieved.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Altium Enterprise Server Collaboration Service requires immediate attention from infrastructure and security teams responsible for managing on-premises deployments. The first step is to identify all instances, confirm their network exposure and criticality, and then assign ownership to assess the risk and plan remediation.
- Ownership: Infrastructure or platform teams.
- Verify: Server reachability and critical asset status.
- Action: Plan and coordinate remediation.