WEG SuperDrive G2 12.0.0 Insecure File Permissions
Posted by deepcore on January 21, 2016 – 3:22 am
SuperDrive suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘C’ flag (Change) for ‘Authenticated Users’ group.
Post a reply
You must be logged in to post a comment.