vendor:
inSync
by:
Matteo Malvica
7.8
CVSS
HIGH
Command injection in inSyncCPHwnet64 RPC service
78
CWE
Product Name: inSync
Affected Version From: 6.6.3
Affected Version To: 6.6.3
Patch Exists: YES
Related CWE: CVE-2020-5752
CPE: a:druva:insync:6.6.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 1909-18363.778
2020
Druva inSync Windows Client 6.6.3 – Local Privilege Escalation
A vulnerability in Druva inSync Windows Client 6.6.3 allows for local privilege escalation due to a lack of path validation. By appending a directory traversal escape sequence at the end of a valid path, an attacker can bypass the 'strncmp' function and execute arbitrary commands with system privileges.
Mitigation:
Ensure that all paths are properly validated before being used in the application.