Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/161334/Millewin-13.39.028-Unquoted-Service-Path-Insecure-Permissions.html | vdb entry third party advisory |
https://www.exploit-db.com/exploits/49530 | vdb entry third party advisory |