Splinterware System Scheduler Pro 5.12 Privilege Escalation
Vulnerability Description
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25359
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- bzyo
References
More from Splinterware
View All →Affected Vendor
Splinterware
View all reports →