Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-23-1561
HistoryOct 19, 2023 - 12:00 a.m.

SolarWinds Access Rights Manager Incorrect Default Permissions Local Privilege Escalation Vulnerability

2023-10-1900:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
5
solarwinds
access rights manager
privilege escalation
vulnerability
installer
incorrect permissions

0.001 Low

EPSS

Percentile

20.2%

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Access Rights Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from incorrect permissions set on product folders created by the installer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.

0.001 Low

EPSS

Percentile

20.2%

Related for ZDI-23-1561