#VU14415 Privilege escalation in SIMATIC WinCC (TIA Portal) and SIMATIC STEP 7 (TIA Portal) - CVE-2018-11453
Published: August 14, 2018 / Updated: August 15, 2018
SIMATIC WinCC (TIA Portal)
SIMATIC STEP 7 (TIA Portal)
Siemens
Description
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists due to improper file permissions in the default installation of TIA Portal. A local unauthenticated attacker can attempt to start TIA Portal after the manipulation, insert specially crafted files and prevent TIA Portal startup (denial-of-service) or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.