SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-191-02 | third party advisory us government resource |