vendor:
ActFax
by:
Craig Freyman
N/A
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: ActFax
Affected Version From: 4.31
Affected Version To: 4.31
Patch Exists: YES
Related CWE:
CPE: a:actfax:actfax:4.31
Platforms Tested:
2012
ActFax 4.31 Local Privilege Escalation Exploit
This exploit allows local users to escalate their privileges in ActFax 4.31. It was discovered by Craig Freyman and published on his blog on August 2012. The exploit uses a payload to execute the cmd.exe command on the target system. The author provides a link to the detailed description of the exploit.
Mitigation:
Apply the latest patch provided by the vendor to fix this vulnerability.