Description
ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.
Problem types
Insertion of Sensitive Information into Externally-Accessible File or Directory
Product status
3.0.1.5 (160622)
3.0.1.1 (160216)
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5360.php (Zero Science Lab Disclosure)
cxsecurity.com/issue/WLB-2016080264 (CXSecurity)
exchange.xforce.ibmcloud.com/vulnerabilities/116487 (IBM X-Force Exchange)
packetstormsecurity.com/files/138565 (Packet Storm Security)
www.exploit-db.com/exploits/40322/ (Reference)
www.vulncheck.com/...e-file-permissions-privilege-escalation (VulnCheck Advisory: ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation)