Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
BID:36396
Info
Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
| Bugtraq ID: | 36396 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 15 2009 12:00AM |
| Updated: | Sep 15 2009 06:41PM |
| Credit: | Maxim A. Kulakov |
| Vulnerable: |
Proland Software Protector Plus Professional 9.1.1 Proland Software Protector Plus 2009 for Windows Server 8.0.E03 Proland Software Protector Plus 2009 for Windows Desktop 8.0.E03 |
| Not Vulnerable: | |
Discussion
Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
Proland Protector Plus is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges, resulting in a complete compromise of the affected computer.
The following versions are affected:
Protector Plus 2009 8.0.E03 for Windows Desktops
Protector Plus 2009 8.0.E03 for Windows Server
Protector Plus Professional 9.1.001
Proland Protector Plus is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges, resulting in a complete compromise of the affected computer.
The following versions are affected:
Protector Plus 2009 8.0.E03 for Windows Desktops
Protector Plus 2009 8.0.E03 for Windows Server
Protector Plus Professional 9.1.001
Exploit / POC
Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
An attacker can use readily available command-line utilities to exploit this issue.
An attacker can use readily available command-line utilities to exploit this issue.
Solution / Fix
Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Proland Protector Plus Insecure Program File Permissions Local Privilege Escalation Vulnerability
References:
References: