I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://geti2p.net/en | product |
https://blog.blazeinfosec.com/security-advisory-i2p-for-windows-local-privilege-escalation/ | third party advisory technical description |