vendor:
Zapya
by:
Arash Khazaei
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Zapya
Affected Version From: 1.803
Affected Version To: 1.803
Patch Exists: NO
Related CWE: N/A
CPE: a:izapya:zapya
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Professional X86, Windows 10 Pro X64
2016
Zapya Desktop Version (‘ZapyaService.exe’) Privilege Escalation
When Zapya Desktop is installed, a service named ZapyaService.exe is placed in the Zapya installation directory. If this file is replaced with a malicious executable file, it will execute with NT/SYSTEM user privilege. To exploit this vulnerability, a Meterpreter executable payload must be generated, the service must be stopped and the malicious executable must be placed in the Zapya installation directory with the exact name of ZapyaService.exe. After starting the service, a reverse Meterpreter shell with NT/SYSTEM privilege will be obtained.
Mitigation:
Ensure that the ZapyaService.exe file is not replaced with a malicious executable file.