vendor:
MilleGPG / MilleGPG5
by:
Andrea Intilangelo
7.4
CVSS
HIGH
Local Privilege Escalation / Incorrect Access Control
264
CWE
Product Name: MilleGPG / MilleGPG5
Affected Version From: 5.9.2002
Affected Version To: 5.9.2002
Patch Exists: YES
Related CWE: CVE-2023-25438
CPE: a:millegpg:millegpg5:5.9.2
Platforms Tested: Microsoft Windows 10 Enterprise x64 22H2, build 19045.2913
2023
MilleGPG5 5.9.2 (Gennaio 2023) – Local Privilege Escalation / Incorrect Access Control
The application is prone to insecure file/folder permissions on its default installation path, wrongly allowing some files to be modified by unprivileged users, malicious process and/or threat actor. Attacker can exploit the weakness abusing the 'write' permission of the main application available to all users on the system or network.
Mitigation:
Ensure that all files and folders have the correct permissions set, and that only privileged users have access to sensitive files and folders.