PT-2018-5054 · Apache · Apache Couchdb
Hyp3Rlinx
+1
·
Published
2018-02-12
·
Updated
2018-03-14
·
CVE-2016-8742
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CouchDB version 2.0.0
Description
The issue concerns a local privilege escalation vulnerability in the Windows installer provided by the Apache CouchDB team. This vulnerability allows a non-privileged user to substitute any executable for the
nssm.exe service launcher, or CouchDB batch or binary files, due to the file permissions inherited from the parent directory. Upon a subsequent service or server restart, the substituted binary will run with administrator privilege.Recommendations
For Apache CouchDB version 2.0.0, update to version 2.0.0.1 to resolve the issue.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Couchdb