PT-2026-25664 · Undefined · Undefined
Published
2026-03-15
·
Updated
2026-03-16
·
CVE-2016-20024
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZKTeco ZKTime.Net version 3.0.1.6
Description
The software contains an insecure file permissions issue that allows users with limited access to gain higher privileges. This is possible by altering executable files. Attackers can take advantage of world-writable permissions within the ZKTimeNet3.0 directory and its files to substitute legitimate executable files with malicious ones, leading to privilege escalation.
Recommendations
Apply the latest security patch or update to a newer version that addresses the insecure file permissions issue.
Restrict write access to the ZKTimeNet3.0 directory and its contents to authorized personnel only.
Regularly audit file permissions within the ZKTimeNet3.0 directory to ensure they are appropriately configured.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined