vendor:
Sysax FTP Automation
by:
bzyo
7.2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Sysax FTP Automation
Affected Version From: 6.9.2000
Affected Version To: 6.9.2000
Patch Exists: NO
Related CWE:
CPE: a:sysax:sysax_ftp_automation:6.9.0
Platforms Tested: Windows 10 x64
2022
Sysax FTP Automation 6.9.0 – Privilege Escalation
Sysax Scheduler Service runs as Local System. By default the application allows for low privilege users to create/run backup jobs other than themselves. By removing the option to run as current user or another, the task will run as System. A low privilege user could abuse this and escalate their privileges to local system.
Mitigation:
Ensure that the 'Login as the following user to run task' option is checked when creating a new task.