vendor:
CouchDB
by:
John Page aka hyp3rlinx
8,8
CVSS
HIGH
Privilege Escalation (Insecure File Permissions)
264
CWE
Product Name: CouchDB
Affected Version From: CouchDB v2.0.0
Affected Version To: CouchDB v2.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:apache:couchdb:2.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2018
Apache CouchDB Local Privilege Escalation
A local attacker with access to a vulnerable system can replace the "nssm.exe" executable with a malicious version, allowing them to add a backdoor Administrator account once the "Apache CouchDB" service is restarted or system rebooted. As Apache CouchDB runs as LOCALSYSTEM, standard users can now execute arbitrary code with the privileges of the SYSTEM.
Mitigation:
Set the correct file permissions on the "nssm.exe" executable to prevent unauthorized access.