header-logo
Suggest Exploit
vendor:
TrueMobile 1300 Wireless System Tray Applet
by:
Unknown
7.5
CVSS
HIGH
Privilege Escalation
Unknown
CWE
Product Name: TrueMobile 1300 Wireless System Tray Applet
Affected Version From: Version 3.10.39.0
Affected Version To: Unknown
Patch Exists: No
Related CWE: Unknown
CPE: a:dell:truemobile_1300_wireless_system_tray_applet
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Privilege Escalation in Dell TrueMobile 1300 Wireless System Tray Applet

A privilege escalation vulnerability exists in the Dell TrueMobile 1300 Wireless System Tray Applet. The software starts with SYSTEM privileges to enable access to the wireless hardware but fails to drop them. This allows a local attacker to manipulate the GUI of the application to spawn arbitrary processes with the privileges of the affected process.

Mitigation:

Unknown
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/9714/info

It has been reported that a privilege escalation vulnerability exists in the Dell TrueMobile 1300 Wireless System Tray Applet. The issue is due to the software starting with SYSTEM privileges, to enable access to the wireless hardware, and subsequently failing to drop them. 

This may allow a local attacker to manipulate the GUI of the vulnerable application to spawn arbitrary processes with the privileges of the affected process.

Although only version 3.10.39.0 of the utility has been reported vulnerable, it is likely that other versions are prone as well.

After launching the affected application, right click in the application window and choose Help -> Help Files and then from the help; Jump to URL C:\WINDOWS\SYSTEM32\CMD.EXE

After launching the affected application, right click in the application window and choose Help -> About. By clicking on a link, Internet Explorer will start with SYSTEM privileges.