vendor:
MilleGPG5
by:
Alessandro 'mindsflee' Salzano
7.5
CVSS
HIGH
Local Privilege Escalation
284
CWE
Product Name: MilleGPG5
Affected Version From: 5.7.2002
Affected Version To: 5.7.2002
Patch Exists: NO
Related CWE:
CPE: millegpg:millegpg5:5.7.2
Platforms Tested: Microsoft Windows 10 Enterprise x64
2021
MilleGPG5 5.7.2 Luglio 2021 (x64) – Local Privilege Escalation
By default, the Authenticated Users group has the modify permission to MilleGPG5 folders/files. A low privilege account can rename the mysqld.exe file located in the bin folder and replace it with a malicious file that would connect back to an attacking computer, giving system level privileges (nt authoritysystem) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file.
Mitigation:
Remove modify permissions for the Authenticated Users group on MilleGPG5 folders/files. Ensure that only trusted users have modify access.