vendor:
Abyss Web Server X1
by:
Tulpa
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Abyss Web Server X1
Affected Version From: 2.11.1
Affected Version To: 2.11.1
Patch Exists: NO
Related CWE: N/A
CPE: a:aprelium:abyss_web_server_x1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86
2016
Abyss Web Server X1 2.11.1 Multiple Local Privilege Escalation
Abyss Web Server installs a service called 'AbyssWebServer' with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. Abyss Web Server also suffers from weak file and folder permissions which could allow an unauthorized user to swop out executable files with their own payload.
Mitigation:
Ensure that all services are running with the least privileges necessary and that all service paths are quoted.