vendor:
StoreGrid
by:
Joey Lane
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: StoreGrid
Affected Version From: 4.0
Affected Version To: 4.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2012
2016
Vembu StoreGrid – Unquoted Service Path Privilege Escalation
StoreGrid is a re-brandable backup solution, which can install 2 services with unquoted service paths. This enables a local privilege escalation vulnerability. To exploit this vulnerability, a local attacker can insert an executable file in the path of either service. Rebooting the system or restarting the service will run the malicious executable with elevated privileges. This was tested on version 4.0, but other versions may be affected as well.
Mitigation:
Ensure that all services have quoted service paths.