vendor:
DashBoard
by:
Gjoko 'LiquidWorm' Krstic
N/A
CVSS
N/A
Insecure Permissions
CWE
Product Name: DashBoard
Affected Version From: 8.5.2001
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2019
Ross Video DashBoard 8.5.1 Insecure Permissions
DashBoard suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'M' flag (Modify) or 'C' flag (Change) for 'Authenticated Users' group.