CVE-2016-20092
HIGHNetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20092. PoCs published by Tulpa.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to the service path being unquoted and running with SYSTEM privileges.
Description
NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.
Exploits (1)
This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to the service path being unquoted and running with SYSTEM privileges.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H