vendor:
Memu Play
by:
Alejandra Sánchez
5.5
CVSS
MEDIUM
Privilege Escalation
269
CWE
Product Name: Memu Play
Affected Version From: 6.0.7
Affected Version To: 6.0.7
Patch Exists: NO
Related CWE:
CPE: a:memu:memu_play:6.0.7
Platforms Tested: Windows 10, Windows 7
2019
Memu Play 6.0.7 – Privilege Escalation (PoC)
Memu Play 6.0.7 suffers from Privilege Escalation due to insecure file permissions. By default, the Authenticated Users group has modify permission to ESM folders/files, allowing a low privilege account to rename the MemuService.exe file and replace it with a malicious file that can connect back to an attacking computer and gain system level privileges. Restarting the computer triggers the execution of the malicious file.
Mitigation:
Ensure proper file permissions are set for the Memu Play application and restrict access to the MemuService.exe file.