PT-2017-17971 · Apc · Apc Ups Daemon
Fragsh3Ll
+1
·
Publicado
2017-06-16
·
Atualizado
2019-10-03
·
CVE-2017-7884
CVSS v3.1
8.4
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
APC UPS Daemon versions through 3.14.14
Description
The default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges. This is possible by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup, due to "RW NT AUTHORITYAuthenticated Users" permissions for %SYSTEMDRIVE%apcupsdbinapcupsd.exe.
Recommendations
For APC UPS Daemon versions through 3.14.14, consider restricting write access to the %SYSTEMDRIVE%apcupsdbinapcupsd.exe file to prevent replacement with a malicious executable. As a temporary workaround, monitor the integrity of the apcupsd.exe file to detect any unauthorized changes.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apc Ups Daemon