PT-2016-4559 · Wampserver · Wampserver

Heliand Dema

·

Publicado

2016-12-27

·

Atualizado

2024-08-06

·

CVE-2016-10031

CVSS v3.1

7.5

Alta

VetorAV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WampServer version 3.0.6
Description The issue arises from weak file permissions in two services, 'wampapache' and 'wampmysqld', which run with SYSTEM privileges. This could allow a local, non-privileged user to execute arbitrary code with elevated privileges by replacing the original files with malicious executable files named mysqld.exe or httpd.exe. The malicious file would be executed as SYSTEM the next time the service starts.
Recommendations For WampServer version 3.0.6, consider restricting access to the services 'wampapache' and 'wampmysqld' to prevent unauthorized file replacements until a proper fix is applied. Additionally, monitor system privileges and file permissions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10031

Produtos afetados

Wampserver