WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://winwastenet.com | url repurposed broken link |
http://nica.it | vendor advisory |
https://packetstormsecurity.com/files/163335/WinWaste.NET-1.0.6183.16475-Local-Privilege-Escalation.html | exploit vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/204780 | vdb entry third party advisory |
https://www.exploit-db.com/exploits/50083 | exploit vdb entry third party advisory |