vendor:
Icecream Ebook Reader, Icecream Screen Recorder, Icecream Slideshow Maker
by:
Tulpa
7.5
CVSS
HIGH
Local Privilege Escalation
CWE
Product Name: Icecream Ebook Reader, Icecream Screen Recorder, Icecream Slideshow Maker
Affected Version From: Icecream Ebook Reader 4.21, Icecream Screen Recorder 4.21, Icecream Screen Recorder 2.12
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Professional x64, Windows XP SP3 x86
2016
Multiple Icecream Apps Local Privilege Escalation
The default installation directory for Icecream Ebook Reader, Icecream Screen Recorder, and Icecream Slideshow Maker have weak folder permissions that grant EVERYONE change/modify privileges. This allows an attacker to execute their own code under any other user running the application.
Mitigation:
Apply proper folder permissions to the installation directories of Icecream Ebook Reader, Icecream Screen Recorder, and Icecream Slideshow Maker.