The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API.
Solution:
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10129-18ea3-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10130-c0959-2.html | third party advisory |