vendor:
O2 Connection Manager
by:
Gjoko 'LiquidWorm' Krstic
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: O2 Connection Manager
Affected Version From: 3.4.R1 (108)
Affected Version To: 3.4.R1 (108)
Patch Exists: NO
Related CWE: N/A
CPE: a:telefonica:o2_connection_manager:3.4.r1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN), Microsoft Windows 7 Ultimate SP1 (EN)
2014
Telefonica O2 Connection Manager 3.4 Local Privilege Escalation Vulnerability
O2 Connection Manager suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable files with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Everyone' group, making the entire directory 'O2 Connection Manager' and its files and sub-dirs world-writable.
Mitigation:
Ensure that the permissions of the O2 Connection Manager directory are properly set and that only authorized users have access to it.