vendor:
WinWaste.NET
by:
Andrea Intilangelo
7,8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: WinWaste.NET
Affected Version From: 1.0.6183.16475
Affected Version To: 1.0.6183.16475
Patch Exists: YES
Related CWE: CVE-2021-34110
CPE: a:nica:winwaste.net:1.0.6183.16475
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 Pro x64 - 20H2 and 21H1
2021
WinWaste.NET 1.0.6183.16475 – Privilege Escalation due Incorrect Access Control
WinWaste.NET version 1.0.6183.16475 (from Nica s.r.l., a Zucchetti Group company) allows a local unprivileged user to replace the executable with a malicious file that will be executed with 'LocalSystem' privileges. Attack Vectors: replacing the WinWasteService.exe and/or any tied .dll used by the software.
Mitigation:
Ensure that the WinWasteService.exe and/or any tied .dll used by the software are not writable by unprivileged users.