PT-2020-20244 · Wing · Wing Ftp Server

Published

2020-03-06

·

Updated

2020-03-09

·

CVE-2020-8634

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wing FTP Server version 6.2.3
Description The issue allows files modified within the HTTP file management interface to be saved with world-readable and world-writable permissions. This could potentially enable a low-privilege user to escalate privileges to root if a sensitive system file were edited in this manner.
Recommendations For Wing FTP Server version 6.2.3, consider restricting access to sensitive system files and modifying the permissions manually after editing to prevent world-readable and world-writable access until a fix is available.

Exploit

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8634

Affected Products

Wing Ftp Server