EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
BID:35883
Info
EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
| Bugtraq ID: | 35883 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2009 12:00AM |
| Updated: | Jul 31 2009 09:05PM |
| Credit: | Nine:Situations:Group |
| Vulnerable: |
Epson Status Monitor 3 |
| Not Vulnerable: | |
Discussion
EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
EPSON Status Monitor is prone to a local privilege-escalation vulnerability that stems from a design error.
An attacker may exploit this vulnerability to overwrite affected files with arbitrary code that will then run with SYSTEM-level privileges. This may facilitate a complete compromise of affected computers.
EPSON Status Monitor 3 is vulnerable; other versions may also be affected.
EPSON Status Monitor is prone to a local privilege-escalation vulnerability that stems from a design error.
An attacker may exploit this vulnerability to overwrite affected files with arbitrary code that will then run with SYSTEM-level privileges. This may facilitate a complete compromise of affected computers.
EPSON Status Monitor 3 is vulnerable; other versions may also be affected.
Exploit / POC
EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
A local attacker can use readily available command-line tools to exploit this issue.
A local attacker can use readily available command-line tools to exploit this issue.
Solution / Fix
EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EPSON Status Monitor Insecure File Permissions Local Privilege Escalation Vulnerability
References:
References: