Permissions, Privileges, and Access Controls in Host type SiteShell for IIS and Host type SiteShell for Apache Windows - CVE-2020-5632

 

Permissions, Privileges, and Access Controls in Host type SiteShell for IIS and Host type SiteShell for Apache Windows - CVE-2020-5632

Published: September 30, 2020


Vulnerability identifier: #VU47167
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5632
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application installs their files with improper access permissions. A local user can modify the service executable files and execute arbitrary code with elevated privileges.


Affected software

Host type SiteShell for IIS
Host type SiteShell for Apache Windows

How to mitigate CVE-2020-5632

Install updates from vendor's website.

Host type SiteShell for IIS - addressed in versions 2.0.0.6, 2.1.0.7, 2.1.1.6, 3.0.0.11, 4.0.0.6, 4.1.0.5, 4.2.0.1
Host type SiteShell for Apache Windows - addressed in versions 2.0.0.6, 2.1.0.7, 2.1.1.6, 3.0.0.11, 4.0.0.6, 4.1.0.5, 4.2.0.1

External References

Related Security Bulletins