Incorrect default permissions in Serv-U FTP Server - CVE-2021-25276
Published: February 3, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions on the Windows "Users" directory. A local user with access to the system can view contents of files and obtain users' password hashes from the "%ProgramData%RhinoSoftServ-UUsers<DOMAIN>" directory.