A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitrary code with NT SYSTEM privileges.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1147 | third party advisory exploit |