vendor:
Hewlett Packard TouchSmart Calendar Service
by:
John Page aka hyp3rlinx
7.5
CVSS
HIGH
Privilege Escalation
CWE
Product Name: Hewlett Packard TouchSmart Calendar Service
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Privilege Escalation in HP TouchSmart Calendar Service
HP Calendar Service uses weak insecure permissions settings on its files/directory as the 'Everyone' group has full access on it. Allowing low privileged users to execute arbitrary code in the security context of ANY other users with elevated privileges on the affected system.