vendor:
701 Client
by:
LiquidWorm
7.2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: 701 Client
Affected Version From: 9.0.1 190410
Affected Version To: 9.0.1 190115
Patch Exists: NO
Related CWE: N/A
CPE: a:soyal_technology_co.ltd:701_client
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Enterprise
2021
SOYAL 701 Client 9.0.1 – Insecure Permissions
The application suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Authenticated Users' group.
Mitigation:
Ensure that the permissions on the executable file are properly set and that only authorized users have access to it.