South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
BID:37955
Info
South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
| Bugtraq ID: | 37955 |
| Class: | Design Error |
| CVE: |
CVE-2009-4606 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 26 2010 12:00AM |
| Updated: | Jan 29 2010 01:12PM |
| Credit: | Nine:Situations:Group::bellick |
| Vulnerable: |
Southrivertech WebDrive 9.02 |
| Not Vulnerable: | |
Discussion
South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
South River Technologies WebDrive is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will result in the complete compromise of affected computers.
WebDrive 9.02 is vulnerable; other versions may also be affected.
South River Technologies WebDrive is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will result in the complete compromise of affected computers.
WebDrive 9.02 is vulnerable; other versions may also be affected.
Exploit / POC
South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting administrator to run the affected application.
An attacker can exploit this issue by enticing an unsuspecting administrator to run the affected application.
Solution / Fix
South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
South River Technologies WebDrive Security Descriptor Local Privilege Escalation Vulnerability
References:
References:
- South River Technologies WebDrive Service Bad Security Descriptor Local Elevatio (Nine:Situations:Group::bellick)
- South River Technologies WebDrive Service Bad Security Descriptor Local Privileg (Trancer)
- WebDrive Homepage (South River Technologies)