PT-2020-14324 · Boxstarter · Boxstarter

Will Dormann

·

Published

2020-10-20

·

Updated

2020-10-30

·

CVE-2020-15264

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Boxstarter versions prior to 2.13.0 Boxstarter versions prior to 3.13.0 is not necessary as 2.13.0 is already mentioned as the fixed version in the context, so we consider versions prior to 2.13.0
Description The issue arises from the Boxstarter installer configuring a directory to be in the system-wide PATH environment variable, which is writable by normal, unprivileged users. This allows an attacker to place a malicious DLL in the directory, such as WptsExtensions.dll, that a privileged service is looking for. When Windows starts, it executes the code in DllMain() with SYSTEM privileges, enabling any unprivileged user to execute code with SYSTEM privileges.
Recommendations For versions prior to 2.13.0, update to version 2.13.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the C:ProgramDataBoxstarter directory to prevent exploitation.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15264
GHSA-RPGX-H675-R3JF

Affected Products

Boxstarter