Advertisement






ESTsoft ALTools Updater Insecure File Permissions Privilege Escalation

CVE Category Price Severity
CVE-2021-42213 CWE-264 $5,000 High
Author Risk Exploitation Type Date
Unknown High Local 2016-09-30
CVSS EPSS EPSSP
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2016090217

Below is a copy:

ESTsoft ALTools Updater Insecure File Permissions Privilege Escalation# Exploit Title: ESTsoft ALTools Updater Insecure File Permissions Privilege Escalation
# Date: 26/09/2016
# Exploit Author: [email protected]
# Vendor Homepage: http://www.estsoft.com/
# Version: 10.4.26.1
# Tested on: Windows 7 32/64bit

====Description====

ESTsoft ALTools Updater for Windows lacks of proper file permissions, creating a vector for privilege escalation attack.
To properly exploit this vulnerability, the local attacker must overwrite the vulnerable file(s) with his malicious ones, as he has full Read/Write rights to the given file.

====Proof-of-Concept====

C:\Program Files\ESTsoft\ALUpdate>icacls ALUpdate.exe
ALUpdate.exe BUILTIN\Users:(I)(F)
             NT AUTHORITY\SYSTEM:(I)(F)
             BUILTIN\Administrators:(I)(F)

Successfully processed 1 files; Failed processing 0 files



Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum