vendor:
IBM Remote Control Software
by:
Unknown
7.5
CVSS
HIGH
Privilege Escalation
Unknown
CWE
Product Name: IBM Remote Control Software
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: Unknown
Unknown
IBM Remote Control Software Privilege Escalation Vulnerability
The IBM Remote Control Software package allows a local user with a user-level account to execute code with administrator privileges. This vulnerability can be exploited by launching arbitrary code from the Process Manager interface, such as usrmgr.exe, musrmgr.exe, and regedt32.exe. The user can use these programs to grant administrator privileges to any account on the host or domain.
Mitigation:
It is recommended to update the IBM Remote Control Software package to the latest version available. Restricting access to the vulnerable service to trusted users only can also help mitigate the risk.