PT-2020-14324 · Boxstarter · Boxstarter
Will Dormann
·
Published
2020-10-20
·
Updated
2020-10-30
·
CVE-2020-15264
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Boxstarter versions prior to 2.13.0
Boxstarter versions prior to 3.13.0 is not necessary as 2.13.0 is already mentioned as the fixed version in the context, so we consider versions prior to 2.13.0
Description
The issue arises from the Boxstarter installer configuring a directory to be in the system-wide PATH environment variable, which is writable by normal, unprivileged users. This allows an attacker to place a malicious DLL in the directory, such as WptsExtensions.dll, that a privileged service is looking for. When Windows starts, it executes the code in
DllMain() with SYSTEM privileges, enabling any unprivileged user to execute code with SYSTEM privileges.Recommendations
For versions prior to 2.13.0, update to version 2.13.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the C:ProgramDataBoxstarter directory to prevent exploitation.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Boxstarter