Huawei eSpace Meeting Service 'eMservice.exe' Local Privilege Escalation Vulnerability
BID:66107
Info
Huawei eSpace Meeting Service 'eMservice.exe' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 66107 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 10 2014 12:00AM |
| Updated: | Mar 10 2014 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: |
Huawei eSpace Meeting V100R001C03SPC201B05 |
| Not Vulnerable: |
Huawei eSpace Meeting V100R001C03SPC202 |
Discussion
Huawei eSpace Meeting Service 'eMservice.exe' Local Privilege Escalation Vulnerability
Huawei eSpace Meeting Service is prone to a local privilege-escalation vulnerability.
Local attackers could exploit this issue to gain elevated privileges.
Huawei eSpace Meeting Service 1.0.0.23 is vulnerable.
Huawei eSpace Meeting Service is prone to a local privilege-escalation vulnerability.
Local attackers could exploit this issue to gain elevated privileges.
Huawei eSpace Meeting Service 1.0.0.23 is vulnerable.
Exploit / POC
Huawei eSpace Meeting Service 'eMservice.exe' Local Privilege Escalation Vulnerability
Local attackers can use readily available commands to exploit this issue.
Local attackers can use readily available commands to exploit this issue.
References
Huawei eSpace Meeting Service 'eMservice.exe' Local Privilege Escalation Vulnerability
References:
References:
- eSpace meeting solution (Huawei Technologies)
- Huawei Home Page (Huawei Technologies)
- Huawei Technologies eSpace Meeting Service 1.0.0.23 Local Privilege Escalation (Zero Science Lab)
- Security Advisory-Improper User Permission Setting Vulnerability in Huawei eSpac (Huawei Technologies)