vendor:
System Scheduler Pro
by:
bzyo
7.5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: System Scheduler Pro
Affected Version From: 5.12
Affected Version To: 5.12
Patch Exists: NO
Related CWE:
CPE: a:splinterware:system_scheduler_pro:5.12
Platforms Tested: Windows 7 SP1 x86
2018
Splinterware System Scheduler Pro 5.12 – Privilege Escalation
Splinterware System Scheduler Pro 5.12 suffers from Privilege Escalation due to insecure file permissions. By default, the Everyone group has the modify permission to System Schedule files, allowing a low privilege account to rename the WService.exe file and replace it with a malicious file that gives system level privileges. The service running as Local System periodically triggers the execution of the malicious file.
Mitigation:
The vendor should update the file permissions to restrict access to critical files and folders. Users should also ensure that the System Scheduler service is not installed if not needed.