Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable file via an alternative data stream.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.ysoft.com/en | vendor advisory |
https://www.ysoft.com/en/legal/ysoft-safeq-flexispooler | vendor advisory |