PT-2026-25664 · Undefined · Undefined

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2016-20024

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZKTeco ZKTime.Net version 3.0.1.6
Description The software contains an insecure file permissions issue that allows users with limited access to gain higher privileges. This is possible by altering executable files. Attackers can take advantage of world-writable permissions within the ZKTimeNet3.0 directory and its files to substitute legitimate executable files with malicious ones, leading to privilege escalation.
Recommendations Apply the latest security patch or update to a newer version that addresses the insecure file permissions issue. Restrict write access to the ZKTimeNet3.0 directory and its contents to authorized personnel only. Regularly audit file permissions within the ZKTimeNet3.0 directory to ensure they are appropriately configured.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2016-20024

Affected Products

Undefined