Summary
This host is installed with South River Technologies WebDrive and is prone to Local Privilege Escalation Vulnerability.
Impact
Successful exploitation will let the local attacker to execute arbitrary commands with an elevated privileges.
Impact Level: System/Application
Solution
Upgrade to South River WebDrive version 9.10 or later For updates refer to http://www.webdrive.com/download/index.html
Insight
The flaw is due to the WebDrive Service being installed without security descriptors, which could be exploited by local attackers to, - stop the service via the stop command
- restart the service via the start command
- execute arbitrary commands with elevated privileges by changing the service 'binPath' configuration.
Affected
South River WebDrive version 9.02 build 2232 and prior on Windows.
References
Severity
Classification
-
CVE CVE-2009-4606 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities