vendor:
WebDrive
by:
Nine:Situations:Group::bellick
7.5
CVSS
HIGH
Privilege Escalation
Unknown
CWE
Product Name: WebDrive
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2009-4606
CPE: Unknown
Platforms Tested: Microsoft Windows XP SP3
Unknown
South River Technologies WebDrive Service Bad Security Descriptor Local Privilege Escalation
This module exploits a privilege escalation vulnerability in South River Technologies WebDrive. Due to an empty security descriptor, a local attacker can gain elevated privileges. Tested on South River Technologies WebDrive 9.02 build 2232 on Microsoft Windows XP SP3. Vulnerability mitigation featured.
Mitigation:
Set correct service security descriptor for the South River Technologies WebDrive Service.