Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.800159
Categoría:Privilege escalation
Título:South River Technologies WebDrive Local Privilege Escalation Vulnerability
Resumen:South River Technologies WebDrive is prone to a local privilege escalation vulnerability.
Descripción:Summary:
South River Technologies WebDrive is prone to a local privilege escalation vulnerability.

Vulnerability Insight:
The flaw is due to the WebDrive Service being installed without
security descriptors, which could be exploited by local attackers to,

- stop the service via the stop command

- restart the service via the start command

- execute arbitrary commands with elevated privileges by changing the
service 'binPath' configuration.

Vulnerability Impact:
Successful exploitation will let the local attacker to execute arbitrary
commands with an elevated privileges.

Affected Software/OS:
South River WebDrive version 9.02 build 2232 and prior on Windows.

Solution:
Upgrade to South River WebDrive version 9.10 or later

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-4606
Bugtraq: 20091020 South River Technologies WebDrive Service Bad Security Descriptor Local Elevation Of Privileges (Google Search)
http://www.securityfocus.com/archive/1/507323/100/0/threaded
http://retrogod.altervista.org/9sg_south_river_priv.html
http://osvdb.org/59080
http://secunia.com/advisories/37083
http://www.vupen.com/english/advisories/2009/2994
XForce ISS Database: webdrive-webdrive-privilege-escalation(53885)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53885
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.