A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and libraries that run as the elevated SYSTEM user on Windows.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.beckmancoulter.com/products/clinical-information-management-tools/remisol-advance | product vendor advisory |
https://pastebin.com/amgw9pE7 | third party advisory |