vendor:
Memu
by:
chuyreds
5.5
CVSS
MEDIUM
Insecure Folder Permissions
269
CWE
Product Name: Memu
Affected Version From: 7.1.2003
Affected Version To: 7.1.2003
Patch Exists: NO
Related CWE:
CPE: a:memuplay:memu:7.1.3
Platforms Tested: Windows 10 Pro x64
2020
Memu Play 7.1.3 – Insecure Folder Permissions
Memu Play 7.1.3 suffers from Privilege Escalation due to insecure file permissions. By default, the Authenticated Users group has modify permission to ESM folders/files, allowing a low privilege account to rename the MemuService.exe file and replace it with a malicious file that can execute with system level privileges. Restarting the computer triggers the execution of the malicious file.
Mitigation:
The vendor should update the folder permissions to restrict modify access for low privilege accounts.