Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-41579-LCDS-LAquis-SCADA-4.3.1.1085-Arbitrary-File-Write — Proof-of-concept exploit for CVE-2021-41579 enabling arbitrary file write/read and RCE via malicious .els project file in LAquis SCADA ≤4.3.1.1085. | Kitploit
Tools/GitHubGitHub/mbanyamer/cve-2021-41579-lcds-laquis-scada-4.3.1.1085-arbitrary-file-write
Payload GenerationVulnerability AnalysisExploitationSCADA/ICS SecurityPenetration TestingBinary Exploitation
GitHubmbanyamer/cve-2021-41579-lcds-laquis-scada-4.3.1.1085-arbitrary-file-write

CVE-2021-41579-LCDS-LAquis-SCADA-4.3.1.1085-Arbitrary-File-Write

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

Proof-of-concept exploit for CVE-2021-41579 enabling arbitrary file write/read and RCE via malicious .els project file in LAquis SCADA ≤4.3.1.1085.

View Repository
177 months agoNot yet reviewed
Share

LAquis SCADA Arbitrary File Write

👨‍💻 Author

Mohammed Idrees Banyamer

🐦 Instagram: @banyamer_security Python Version CVE Author

Proof-of-Concept exploit for CVE-2021-41579 - Arbitrary file write via malicious .els project file in LCDS LAquis SCADA ≤ 4.3.1.1085.


🚨 Vulnerability Description

CVE-2021-41579 is a client-side vulnerability in LCDS LAquis SCADA versions ≤ 4.3.1.1085.

An attacker can craft a malicious .els project file containing path traversal sequences (..\..\..\). When a victim opens the file and clicks "Play" (runtime/simulation mode), LAquis bypasses all security/consent prompts and resolves the traversed paths without sanitization.

This allows:

  • Arbitrary file write to locations writable by the current user
  • Arbitrary file read of system/project files
  • Remote Code Execution (via Startup folder persistence or malicious DLLs)

🎯 Affected Versions

StatusVersion
❌ VulnerableLAquis SCADA ≤ 4.3.1.1085
✅ PatchedLAquis SCADA ≥ 4.3.2.1086

Tested on: Windows 10 x64, Windows 11 x64


💥 Impact

VectorDescription
CVSS v37.8 (High) - AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
File WriteDrop files to Startup → RCE on next boot
File ReadDump credentials, project source code, system files
PrivilegeRuns with victim's privileges (often Admin in SCADA environments)

🔬 Technical Details

Root Cause

  1. Client-side validation only - Paths are checked when opening the file, but not revalidated during runtime
  2. Play mode bypass - Clicking "Play" assumes the project is already trusted
  3. No path normalization - ..\..\ sequences are passed directly to filesystem APIs
  4. Widespread path fields - Images, scripts, logs, exports all use writable path strings

Vulnerability Flow

graph LR
    A[Attacker crafts malicious .els] --> B[Victim opens file]
    B --> C[Clicks 'Play' button]
    C --> D[LAquis resolves path at runtime]
    D --> E[No re-validation]
    E --> F[Path traversal triggered]
    F --> G[File written/read at target location]

🛠️ Usage

git clone https://github.com/mbanyamer/CVE-2021-41579.git
cd CVE-2021-41579
pip install -r requirements.txt  # if applicable
Download Tool