vendor:
EmEditor
by:
SajjadBnd
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: EmEditor
Affected Version From: 19.8
Affected Version To: 19.8
Patch Exists: NO
Related CWE: N/A
CPE: a:emeditor:emeditor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win10 Professional x64
2020
EmEditor 19.8 – Insecure File Permissions
EmEditor is a fast, lightweight, yet extensible, easy-to-use text editor for Windows. An attacker can replace any *.exe files with any executable malicious file and wait to get SYSTEM or Administrator rights.
Mitigation:
Ensure that the permissions of the files are set to the minimum required for the application to function properly.