PT-2019-10120 · Microvirt · Memu

Daveysec

+1

·

Publicado

2019-03-13

·

Atualizado

2019-10-03

·

CVE-2018-20621

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microvirt MEmu version 6.0.6
Description: An issue was discovered in Microvirt MEmu. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.
Recommendations: For Microvirt MEmu version 6.0.6, consider restricting access to the MemuService.exe service binary to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20621

Produtos afetados

Memu