MAST RunAs Professional Local Privilege Escalation Vulnerability
BID:13949
Info
MAST RunAs Professional Local Privilege Escalation Vulnerability
| Bugtraq ID: | 13949 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2005 12:00AM |
| Updated: | Jun 14 2005 12:00AM |
| Credit: | Discovery is credited to traxx. |
| Vulnerable: |
MAST RunAs Professional 3.5.1 |
| Not Vulnerable: | |
Discussion
MAST RunAs Professional Local Privilege Escalation Vulnerability
RunAs Professional (RunAsP.exe) is affected by a local privilege escalation vulnerability.
This issue presents itself because the affected application fails to verify the executable prior to running it with higher privileges.
RunAs Professional 3.5.1 is affected by this vulnerability. Other versions may be prone to this issue as well.
RunAs Professional (RunAsP.exe) is affected by a local privilege escalation vulnerability.
This issue presents itself because the affected application fails to verify the executable prior to running it with higher privileges.
RunAs Professional 3.5.1 is affected by this vulnerability. Other versions may be prone to this issue as well.
Exploit / POC
MAST RunAs Professional Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MAST RunAs Professional Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MAST RunAs Professional Local Privilege Escalation Vulnerability
References:
References: