vendor:
exacqVision ESM
by:
bzyo
7.5
CVSS
HIGH
Privilege Escalation
287
CWE
Product Name: exacqVision ESM
Affected Version From: 5.12.2.150128
Affected Version To: 5.12.2.150128
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 SP1 x86, Windows 10 x64
2019
exacqVision ESM 5.12.2 – Privilege Escalation
exacqVision ESM 5.12.2 suffers from Privilege Escalation due to insecure file permissions. By default, the Authenticated Users group has the modify permission to ESM folders/files, allowing a low privilege account to rename the enterprisesystemmanager.exe file and replace it with a malicious file that can give system level privileges. Restarting the computer triggers the execution of the malicious file.
Mitigation:
Ensure proper file permissions are set for ESM folders/files, restricting modify access to only authorized users.