vendor:
Smartfren Connex EC 1261-2 UI
by:
X-Cisadane
7,2
CVSS
HIGH
Local Privilege Escalation Vulnerability
264
CWE
Product Name: Smartfren Connex EC 1261-2 UI
Affected Version From: 21.005.15.03.836
Affected Version To: 21.005.15.03.836
Patch Exists: NO
Related CWE: N/A
CPE: a:smartfren:smartfren_connex_ec_1261-2_ui
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win32 & Win64
2012
Smartfren Connex EC 1261-2 UI OUC Local Privilege Escalation Vulnerability
Improper file permissions on executable file of the application could result on Local Privilege Escalation Vulnerability. It can be used by a simple user that can change the executable file with a binary of choice. The binary (ouc.exe) is set by default to Startup and will be executed with SYSTEM privileges.
Mitigation:
Ensure that the executable file of the application has proper file permissions.