Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
South River Technologies WebDrive Local Privilege Escalation Vulnerability
Information
Severity
Severity
High
Family
Family
Privilege escalation
CVSSv2 Base
CVSSv2 Base
7.2
CVSSv2 Vector
CVSSv2 Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
14 years ago
Modified
Modified
5 years ago
Summary
This host is installed with South River Technologies WebDrive and is prone to Local Privilege Escalation Vulnerability.
Insight
Insight
The flaw is due to the WebDrive Service being installed without security descriptors, which could be exploited by local attackers to, - stop the service via the stop command - restart the service via the start command - execute arbitrary commands with elevated privileges by changing the service 'binPath' configuration.
Affected Software
Affected Software
South River WebDrive version 9.02 build 2232 and prior on Windows.
Solution
Solution
Upgrade to South River WebDrive version 9.10 or later