vendor:
Rapid7 Nexpose Installer
by:
Angelo D'Amato
N/A
CVSS
N/A
Local Privilege Escalation
Unknown
CWE
Product Name: Rapid7 Nexpose Installer
Affected Version From: Unknown
Affected Version To: 6.6.39
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows 10 Enterprise, x64-based PC, Microsoft Windows Server 2016 Standard, x64-based PC
2020
Rapid7 Nexpose Installer 6.6.39 – ‘nexposeengine’ Unquoted Service Path
Rapid7 Nexpose installer version prior to 6.6.40 uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path, allowing local privilege escalation.
Mitigation:
Unknown