vendor:
.NET Runtime Optimization Service
by:
XenoMuta
7.2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: .NET Runtime Optimization Service
Affected Version From: v2.0.50727
Affected Version To: v2.0.50727
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:o:microsoft:.net_runtime_optimization_service:2.0.50727
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP (sp3), 2003 R2, 7
2011
.NET Runtime Optimization Service Privilege Escalation
This service's EXE file can be overwritten by any non-admin domain user and local power users (which are the default permissions set). This exploit compiles to a service that uses the original service's id.
Mitigation:
Ensure that the permissions set for the service's EXE file are secure and only accessible to authorized users.