vendor:
SopCast
by:
Gjoko 'LiquidWorm' Krstic
7.2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: SopCast
Affected Version From: 3.4.2007
Affected Version To: 3.4.7.45585
Patch Exists: NO
Related CWE: N/A
CPE: a:sopcast:sopcast:3.4.7.45585
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2011
SopCast 3.4.7 (Diagnose.exe) Improper Permissions
SopCast is vulnerable to an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (full control) for the 'Everyone' group, for the 'Diagnose.exe' binary file which is bundled with the SopCast installation package.
Mitigation:
Restrict the permissions of the 'Diagnose.exe' binary file to only allow access to the Administrators group.