vendor:
ProShow Producer
by:
Julien Ahrens
N/A
CVSS
N/A
Incorrect Default Permissions [CWE-276]
276
CWE
Product Name: ProShow Producer
Affected Version From: Photodex ProShow Producer v5.0.3310
Affected Version To: Photodex ProShow Producer v5.0.3310
Patch Exists: NO
Related CWE: -
CPE: Photodex/ProShow_Producer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Ultimate 64 Bit (EN), Microsoft Windows 8 Enterprise 32 Bit (EN)
2013
Exploit-DB Note: Vuln still in 6.0.3410 as well as ‘Photodex ProShow Gold’
A local privilege escalation vulnerability has been identified in Photodex ProShow Producer v5.0.3310. Insecure file permissions on the executable file 'scsiaccess.exe', which is used by the application service 'ScsiAccess' under the SYSTEM account, may allow a less privileged user to gain access to SYSTEM privileges. A local attacker or compromised process is able to replace the original application binary with a malicious application which will be executed by a victim user or after a ScsiAccess service restart.
Mitigation:
None