Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-14327. PoCs published by Osanda Malith Jayathissa.
AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in EE 4GEE Mini EE40_00_02.00_44 due to weak folder permissions and an unquoted service path. The PoC shows how an attacker can replace the executable in the vulnerable directory to achieve escalation.
Description
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Connecton\EE40" and "Web Connecton\EE40\BackgroundService" directories, which allows local users to gain privileges, as demonstrated by inserting a Trojan horse ServiceManager.exe file into the "Web Connecton\EE40\BackgroundService" directory.
Exploits (1)
This exploit demonstrates a local privilege escalation vulnerability in EE 4GEE Mini EE40_00_02.00_44 due to weak folder permissions and an unquoted service path. The PoC shows how an attacker can replace the executable in the vulnerable directory to achieve escalation.
References (5)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H