PT-2020-13354 · Msi · Dragon Center
Published
2020-05-18
·
Updated
2020-05-20
·
CVE-2020-13149
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dragon Center versions prior to 2.6.2003.2401
Description
The issue is related to weak permissions on the "%PROGRAMDATA%MSIDragon Center" folder in Dragon Center, which allows local authenticated users to overwrite system files and gain escalated privileges. Attack methods include changing the Recommended App binary within
App.json or using this part of %PROGRAMDATA% for mounting an RPC Control directory.Recommendations
For versions prior to 2.6.2003.2401, update to version 2.6.2003.2401 or later to resolve the issue. As a temporary workaround, consider restricting access to the "%PROGRAMDATA%MSIDragon Center" folder to prevent local authenticated users from overwriting system files. Avoid using the
App.json file for storing sensitive information until the issue is resolved.Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dragon Center