vendor:
Millewin
by:
Andrea Intilangelo
8.8
CVSS
HIGH
Insecure Permissions
276
CWE
Product Name: Millewin
Affected Version From: 13.39.028
Affected Version To: 13.39.146.1
Patch Exists: YES
Related CWE: CVE-2021-3394
CPE: cpe:a:millewin:millewin:13.39.146.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Enterprise x64
2021
Millewin 13.39.146.1 – Local Privilege Escalation
The application is prone to insecure permissions in its folders that allows unprivileged user complete control. An attacker can exploit the vulnerability by arbitrarily replacing file(s) invoked by service(s)/startup regkey impacted. File(s) will be executed with SYSTEM privileges.
Mitigation:
The vendor has released a patch to address the issue.