CVE-2018-13101
Summary
| CVE | CVE-2018-13101 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-03 12:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege escalation via execution of attacker controlled binaries. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redswimmer | Kiosksimple | 1.4.7.0 | All | All | All |
| Application | Redswimmer | Kiosksimple | 1.4.7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| research/VS-2018-026.md at master · VerSprite/research · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.