vendor:
BarracudaDrive
by:
Bobby Cooke & Adeeb Shah
7.5
CVSS
HIGH
Insecure Folder Permissions
276, 732
CWE
Product Name: BarracudaDrive
Affected Version From: v6.5
Affected Version To: v6.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro
2020
BarracudaDrive v6.5 – Insecure Folder Permissions
Insecure Service File Permissions in bd service in Real Time Logics BarracudaDrive v6.5 allows local low-privilege attacker to escalate privileges to admin via replacing the bd.exe file and restarting the computer where the malicious code will be executed as 'LocalSystem' on the next startup.
Mitigation:
Apply proper folder and file permissions to restrict unauthorized access. Regularly update and patch the software.