vendor:
HP Connected Backup
by:
Peter Lapp
7.2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: HP Connected Backup
Affected Version From: 8.8.2.0
Affected Version To: 8.8.2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:hewlett_packard:hp_connected_backup
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64
2020
HP Connected Backup Privilege Escalation
This exploit is used to gain privilege escalation on HP Connected Backup version 8.8.2.0 on Windows 7 x64. It involves copying cmd.exe to a world-writeable folder, creating a backup for the file, and then using the backup to gain privilege escalation.
Mitigation:
Ensure that all files are stored in secure locations and that all users have the least amount of privileges necessary to perform their job.