CVE Database
/

CVE-2016-8742

Back to search

CVE-2016-8742

Published: Feb 12, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.

VendorProductVersions

Apache Software Foundation

Apache CouchDB

affected
2.0.0 (Windows platform only)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now