Operation Technology ETAP 14.1.0 Local Privilege Escalation
Posted by deepcore on May 24, 2016 – 6:29 pm
ETAP suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘C’ flag (Change) for ‘Authenticated Users’ group. Version 14.1.0.0 is affected.
Post a reply
You must be logged in to post a comment.