Lucene search

K
zdiKernelsmith - Zero Day InitiativeZDI-15-035
HistoryFeb 10, 2015 - 12:00 a.m.

Motorola Scanner SDK CoreScanner.exe Privilege Escalation Vulnerability

2015-02-1000:00:00
kernelsmith - Zero Day Initiative
www.zerodayinitiative.com
49

0.001 Low

EPSS

Percentile

50.2%

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on vulnerable installations of Motorola Scanner SDK. Authentication is not required to exploit this vulnerability. The specific flaw exists within the file permissions (ACLs) on an installed directory. CoreScanner.exe is vulnerable to tampering by all users. A local attacker can leverage this vulnerability to raise privileges and execute code under the context of SYSTEM.

0.001 Low

EPSS

Percentile

50.2%

Related for ZDI-15-035