Back to CVE List

CVE-2016-20092

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-428
Source
NVD
Vendor
Netdrive
Product
NetDrive

External References

Discussion (0)

Add Comment

No comments yet. Be the first!