Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2j7-jqw5-568r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.

EPSS

Процентиль: 87%
0.03617
Низкий

Связанные уязвимости

CVSS3: 9.9
nvd
около 6 лет назад

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.

EPSS

Процентиль: 87%
0.03617
Низкий