Description
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/134523/Polycom-BTOE-Connector-2.3.0-Local-Privilege-Escalation.html
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Nov/88
Various Sources x_refsource_misc
https://github.com/sbaresearch/advisories/tree/public/2015/Polycom_20150513
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
12.3%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-275
Status
published
Products (1)
polycom/btoe_connector
< 2.3.0
Published
Aug 28, 2017
Tracked Since
Feb 18, 2026