vendor:
Lotus Notes
by:
ParagonSec
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Lotus Notes
Affected Version From: 8.5
Affected Version To: 9.0
Patch Exists: YES
Related CWE: CVE-2015-0179
CPE: 2.3:a:ibm:lotus_notes:8.5:*:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Enterprise
2017
Lotus Notes Diagnostic Tool (nsd.exe) Privelege Escalation
Lotus Notes Diagnostic Tool (nsd.exe) runs under NT Authority/System rights. This can be leveraged to run a program under the System context and elevate local privileges. First you need to execute nsd.exe under the monitor/CLI mode: > nsd.exe -monitor. Next, after NSD finishes loading you can execute any program under the System context. In this example we will execute CMD. nsd> LOAD CMD. You will see that cmd is opened as System now. Also, NSD can be used to attach, kill processes or create memory dumps under the System context.
Mitigation:
This has been fixed on release 9.0.1 FP3 and 8.5.3 FP6.