Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mq4-39cv-h79m

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

EPSS

Процентиль: 50%
0.00272
Низкий

Связанные уязвимости

nvd
около 16 лет назад

South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

EPSS

Процентиль: 50%
0.00272
Низкий