WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://winwastenet.com | broken link url repurposed |
http://nica.it | vendor advisory |
https://packetstormsecurity.com/files/163335/WinWaste.NET-1.0.6183.16475-Local-Privilege-Escalation.html | third party advisory exploit vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/204780 | third party advisory vdb entry |
https://www.exploit-db.com/exploits/50083 | third party advisory exploit vdb entry |