CVE Database
/

CVE-2017-7884

Back to search

CVE-2017-7884

Published: Jun 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe.

VendorProductVersions

n/a

n/a

affected
n/a

References

1038707
vdb-entry
x_refsource_SECTRACK
99092
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now