AOL Client Software Local Privilege Escalation Vulnerability
BID:14530
Info
AOL Client Software Local Privilege Escalation Vulnerability
| Bugtraq ID: | 14530 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 09 2005 12:00AM |
| Updated: | Aug 09 2005 12:00AM |
| Credit: | Nicholas Staff <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
AOL Client Software 9.0 |
| Not Vulnerable: | |
Discussion
AOL Client Software Local Privilege Escalation Vulnerability
AOL client software is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the software to properly secure its installation path against local modifications.
This issue allows local users to replace the affected binary with an executable of their choice, allowing them to execute arbitrary code with SYSTEM privileges. This facilitates the complete compromise of the local computer.
AOL version 9.0 Security Edition is reported susceptible to this vulnerability; other versions may also be affected.
AOL client software is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the software to properly secure its installation path against local modifications.
This issue allows local users to replace the affected binary with an executable of their choice, allowing them to execute arbitrary code with SYSTEM privileges. This facilitates the complete compromise of the local computer.
AOL version 9.0 Security Edition is reported susceptible to this vulnerability; other versions may also be affected.
Exploit / POC
AOL Client Software Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
AOL Client Software Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.