vendor:
Bulk SMS Desktop Software
by:
Tulpa
5.5
CVSS
MEDIUM
Local Privilege Escalation
269
CWE
Product Name: Bulk SMS Desktop Software
Affected Version From: 3.43
Affected Version To: 3.43
Patch Exists: NO
Related CWE:
CPE: a:winsms:desktop_software:3.43
Platforms Tested: Windows 10 Professional x64, Windows XP SP3 x86
2016
WinSMS 3.43 Local Privilege Escalation
WinSMS installs with weak folder permissions, allowing any user to execute code against other users running the application. Additionally, sensitive information such as the proxy server password is stored in plain text.
Mitigation:
The vendor should update the folder permissions to restrict access and encrypt sensitive information.