vendor:
Filezilla FTP Client
by:
Cyril Vallicari
7,5
CVSS
HIGH
Privilege Escalation
78
CWE
Product Name: Filezilla FTP Client
Affected Version From: 3.17.0.0
Affected Version To: 3.17.0.0
Patch Exists: YES
Related CWE: Asked it is reviewed (11/08/2016)
CPE: filezilla:filezilla_ftp_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Filezilla 3.17.0.0 windows installer Privileges Escalation via unquoted path vulnerability
The installer of Filezilla for Windows version 3.17.0.0 and probably prior and prone to unquoted path vulnerability. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Upgrade to Filezilla version 3.17.0.1 or later