When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/ | third party advisory exploit |