#VU24771 Incorrect default permissions in EasyInstall


Published: 2020-01-30

Vulnerability identifier: #VU24771

Vulnerability risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-19896

CWE-ID: CWE-276

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
EasyInstall
Client/Desktop applications / Other client software

Vendor: IXP Data

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows remote authenticated attacker to execute arbitrary code in the context of "NT AUTHORITYSYSTEM" on the target server and clients.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

EasyInstall: 6.2.13723


External links
http://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-deployment-software


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability