vendor:
Microsoft Source Code Analyzer for SQL Injection
by:
Gjoko 'LiquidWorm' Krstic
7.2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: Microsoft Source Code Analyzer for SQL Injection
Affected Version From: 1.3.30601.30705
Affected Version To: 1.3.30601.30705
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:source_code_analyzer_for_sql_injection
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2011
Microsoft Source Code Analyzer for SQL Injection 1.3 Improper Permissions
The package suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'C' flag (Change(write)) for the 'Everyone' group, for the binary file msscasi_asp.exe and the package itself, msscasi_asp_pkg.exe.
Mitigation:
Ensure that the permissions for the binary file msscasi_asp.exe and the package itself, msscasi_asp_pkg.exe are set to the appropriate level.