Executive brief
HCL MyCloud is affected by a security vulnerability due to the use of an outdated or unmaintained version of the Microsoft IIS web server. This could allow a highly privileged attacker to exploit known weaknesses in the underlying server software to potentially access sensitive information. Because the attack requires high-level administrative access and specific network conditions, the overall risk to the organization is considered low.
Technical details
HCL MyCloud version 10.8.2 utilizes a version of Microsoft IIS Server that contains known vulnerabilities or is no longer maintained (CWE-1104). An attacker with high privileges (PR:H) could exploit these underlying weaknesses over a network, though the attack complexity is high (AC:H). Successful exploitation could lead to a limited loss of confidentiality. The vulnerability was identified by HCL Software, and users are encouraged to review the associated security bulletin for remediation steps.
Affected products
- HCL Software MyCloud 10.8.2
Timeline
- 2026-07-21: advisory: Initial disclosure by HCL Software and NVD publication.