Invensys Wonderware InTouch Default Universal NetDDE Share Privilege Escalation Vulnerability
BID:26496
Info
Invensys Wonderware InTouch Default Universal NetDDE Share Privilege Escalation Vulnerability
| Bugtraq ID: | 26496 |
| Class: | Design Error |
| CVE: |
CVE-2007-6033 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2007 12:00AM |
| Updated: | Dec 18 2007 08:06PM |
| Credit: | Neutralbit, with assistance from Digital Bond, discovered this issue. |
| Vulnerable: |
Wonderware InTouch 8.0 |
| Not Vulnerable: | |
Discussion
Invensys Wonderware InTouch Default Universal NetDDE Share Privilege Escalation Vulnerability
Invensys Wonderware InTouch is prone to a privilege-escalation vulnerability because of poor default permissions on a NetDDE share.
Attackers can exploit this issue to execute arbitrary applications that accept NetDDE connections. This can compromise the application and possibly the underlying computer.
InTouch 8.0 is vulnerable.
Invensys Wonderware InTouch is prone to a privilege-escalation vulnerability because of poor default permissions on a NetDDE share.
Attackers can exploit this issue to execute arbitrary applications that accept NetDDE connections. This can compromise the application and possibly the underlying computer.
InTouch 8.0 is vulnerable.
Exploit / POC
Invensys Wonderware InTouch Default Universal NetDDE Share Privilege Escalation Vulnerability
To exploit this issue, an attacker can use readily available NetDDE utilities.
To exploit this issue, an attacker can use readily available NetDDE utilities.
Solution / Fix
Invensys Wonderware InTouch Default Universal NetDDE Share Privilege Escalation Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Solution:
The vendor released fixes to address this issue. Please see the references for more information.