CVE-2016-20086
HIGHVembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20086. PoCs published by Joey Lane.
AI-analyzed exploit summary This is a technical writeup describing an unquoted service path privilege escalation vulnerability in Vembu StoreGrid. The vulnerability allows a local attacker to escalate privileges by placing a malicious executable in the path of the service, which will be executed with elevated privileges upon service restart.
Description
Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and restart the service to execute code with LocalSystem privileges.
Exploits (1)
This is a technical writeup describing an unquoted service path privilege escalation vulnerability in Vembu StoreGrid. The vulnerability allows a local attacker to escalate privileges by placing a malicious executable in the path of the service, which will be executed with elevated privileges upon service restart.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H