CVE-2022-0556 – ZyXel AP Configurator Incorrect Permission Assignment Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-0556
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator. Una vulnerabilidad de escalada de privilegios local causada por la asignación incorrecta de permisos en algunos directorios de Zyxel AP Configurator (ZAC) versión 1.1.4, que podría permitir a un atacante ejecutar código arbitrario como administrador local This vulnerability allows local attackers to escalate privileges on affected installations of ZyXel AP Configurator. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the installer. The issue results from incorrect permissions set on a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an Administrator. • https://www.zyxel.com/support/Zyxel-security-advisory-for-local-privilege-escalation-vulnerability-of-AP-Configurator.shtml • CWE-269: Improper Privilege Management CWE-732: Incorrect Permission Assignment for Critical Resource •