CVE-2018-17908
Advantech WebAccess Client Improper Access Control Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
WebAccess en versiones 8.3.2 y anteriores. Durante la instalación, el instalador de la aplicación deshabilita el control de acceso de los usuario y no lo rehabilita tras completar la instalación. Esto podría permitir que un atacante ejecute código arbitrario elevado.
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Advantech WebAccess Client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the access control that is set and modified during the installation of the product. The product installation weakens access control restrictions by disabling User Account Control. An attacker can leverage this vulnerability to execute arbitrary code in the context of the Administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-02 CVE Reserved
- 2018-10-29 CVE Published
- 2023-10-23 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105736 | Third Party Advisory | |
http://www.securitytracker.com/id/1041957 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-18-298-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Advantech Search vendor "Advantech" | Webaccess Search vendor "Advantech" for product "Webaccess" | <= 8.3.2 Search vendor "Advantech" for product "Webaccess" and version " <= 8.3.2" | - |
Affected
|