Description
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
Problem types
CWE-250 Execution with Unnecessary Privileges
Product status
1.2.7.23180
References
retest.dk/...ion-vulnerability-found-in-local-admin-service/
retest.dk/...ion-vulnerability-found-in-local-admin-service/
www.danofficeit.com/howwedoit/workplace/management/