Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://ilex.com | vendor advisory |
http://signgo.com | third party advisory |
https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/ | third party advisory exploit |