PT-2018-5054 · Apache · Apache Couchdb

Hyp3Rlinx

+1

·

Published

2018-02-12

·

Updated

2018-03-14

·

CVE-2016-8742

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache CouchDB version 2.0.0
Description The issue concerns a local privilege escalation vulnerability in the Windows installer provided by the Apache CouchDB team. This vulnerability allows a non-privileged user to substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files, due to the file permissions inherited from the parent directory. Upon a subsequent service or server restart, the substituted binary will run with administrator privilege.
Recommendations For Apache CouchDB version 2.0.0, update to version 2.0.0.1 to resolve the issue.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8742

Affected Products

Apache Couchdb