vendor:
Wampserver
by:
Heliand Dema
7.5
CVSS
HIGH
Weak File Permissions
269
CWE
Product Name: Wampserver
Affected Version From: Wampserver 3.0.6 32 bit x86
Affected Version To: Wampserver 3.0.6 32 bit x86
Patch Exists: NO
Related CWE:
CPE: a:wampserver_project:wampserver:3.0.6
Platforms Tested: Windows 7 Ultimate SP1 (EN)
2016
Weak File Permissions in Wampserver
Wampserver installs two services called 'wampapache' and 'wampmysqld' with weak file permission running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Apply appropriate file permissions to the 'wampapache' and 'wampmysqld' services to prevent unauthorized execution of arbitrary code.