KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.kramerav.com/us/product/viaware | exploit product vendor advisory |
http://packetstormsecurity.com/files/166623/Kramer-VIAware-Remote-Code-Execution.html | exploit vdb entry third party advisory |