Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50931. PoCs published by Aryan Chehreghani.
AI-analyzed exploit summary This exploit demonstrates insecure file permissions in TeamSpeak 3.5.6, allowing an attacker to replace executable files with malicious ones for privilege escalation. The PoC shows that critical executables are writable by SYSTEM, Administrators, and the local Administrator.
Description
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access.
Exploits (1)
This exploit demonstrates insecure file permissions in TeamSpeak 3.5.6, allowing an attacker to replace executable files with malicious ones for privilege escalation. The PoC shows that critical executables are writable by SYSTEM, Administrators, and the local Administrator.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H