Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/102278 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2017/Dec/83 | third party advisory mailing list |
https://hackerone.com/reports/140793 | issue tracking third party advisory |
https://www.exploit-db.com/exploits/43390/ | exploit vdb entry third party advisory |
http://packetstormsecurity.com/files/145533/Ubiquiti-UniFi-Video-3.7.3-Windows-Local-Privilege-Escalation.html | vdb entry third party advisory |