vendor:
701 Server
by:
LiquidWorm
7.2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: 701 Server
Affected Version From: 9.0.1 190322
Affected Version To: 8.0.6 181227
Patch Exists: NO
Related CWE: N/A
CPE: a:soyal_technology:701_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Enterprise
2021
SOYAL 701 Server 9.0.1 – Insecure Permissions
The application suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Everyone' and 'Authenticated Users' group.
Mitigation:
Ensure that the permissions on the executable files are properly set and that only authorized users have access to them.