Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
BID:100454
CVE-2017-9644 |Info
Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 100454 |
| Class: | Design Error |
| CVE: |
CVE-2017-9644 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2017 12:00AM |
| Updated: | Aug 23 2017 12:00AM |
| Credit: | Gjoko Krstic from Zero Science Lab |
| Vulnerable: |
Automated Logic Corporation (ALC) WebCTRL 6.5 Automated Logic Corporation (ALC) WebCTRL 6.1 Automated Logic Corporation (ALC) WebCTRL 6.0 Automated Logic Corporation (ALC) WebCTRL 5.5 Automated Logic Corporation (ALC) WebCTRL 5.2 Automated Logic Corporation (ALC) SiteScan Web 6.5 Automated Logic Corporation (ALC) SiteScan Web 6.1 Automated Logic Corporation (ALC) SiteScan Web 5.5 Automated Logic Corporation (ALC) SiteScan Web 5.2 Automated Logic Corporation (ALC) i-Vu 6.5 Automated Logic Corporation (ALC) i-Vu 6.0 Automated Logic Corporation (ALC) i-Vu 5.5 Automated Logic Corporation (ALC) i-Vu 5.2 |
| Not Vulnerable: | |
Discussion
Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
Multiple Automated Logic Corporation (ALC) Products are prone to local privilege-escalation vulnerability.
Local attackers can exploit this issue execute arbitrary code with elevated privileges.
The following products are affected:
ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior.
ALC WebCTRL, SiteScan Web 6.1 and prior.
ALC WebCTRL, i-Vu 6.0 and prior.
ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior.
ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior.
Multiple Automated Logic Corporation (ALC) Products are prone to local privilege-escalation vulnerability.
Local attackers can exploit this issue execute arbitrary code with elevated privileges.
The following products are affected:
ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior.
ALC WebCTRL, SiteScan Web 6.1 and prior.
ALC WebCTRL, i-Vu 6.0 and prior.
ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior.
ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior.
Exploit / POC
Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Automated Logic Corporation Products CVE-2017-9644 Local Privilege Escalation Vulnerability
References:
References:
- Automated Logic Corporation (ALC) Homepage (Automated Logic Corporation (ALC))
- ICSA-17-234-01: Automated Logic Corporation WebCTRL, i-VU, SiteScan (ICS CERT)