CVE-2020-23834
Summary
| CVE | CVE-2020-23834 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-04 04:15:00 UTC |
| Updated | 2020-09-16 15:34:00 UTC |
| Description | Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realtimelogic | Barracudadrive | 6.5 | All | All | All |
| Application | Realtimelogic | Barracudadrive | 6.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BarracudaDrive v6.5 - Insecure Folder Permissions - Windows local Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| GitHub - boku7/BarracudaDrivev6.5-LocalPrivEsc: Insecure Service File Permissions in bd service in Real Time Logics BarracudaDrive v6.5 allows local attackers to escalate privileges to admin via replacing the bd.exe file and restarting the computer where it will be run as 'LocalSystem' on the next startup automatically. | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.