vendor:
WebCTRL
by:
Security Researcher
7,8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: WebCTRL
Affected Version From: ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior
Affected Version To: ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior
Patch Exists: YES
Related CWE: CVE-2020-12345
CPE: a:automated_logic:webctrl
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN)
2020
Automated Logic WebCTRL 6.5 Insecure File Permissions Privilege Escalation
WebCTRL server/service suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'M' flag (Modify) or 'C' flag (Change) for 'Authenticated Users' group. The application suffers from an unquoted search path issue as well impacting the service 'WebCTRL Service' for Windows deployed as part of WebCTRL server solution. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Automated Logic Corporation has released a patch to address this vulnerability.