An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unprivileged local attacker to read the encrypted dbuser and dbpassword values for the UMS superuser.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.igel.com/igel-solution-family/universal-management-suite/ | product vendor advisory |
https://github.com/atredispartners/advisories/blob/master/ATREDIS-2022-0002.md | third party advisory exploit |