Skip to content

Boxstarter folder allows write access for standard users

High
pauby published GHSA-rpgx-h675-r3jf Oct 20, 2020

Package

No package listed

Affected versions

<= 2.12.0

Patched versions

2.13.0

Description

Description

The Boxstarter installer configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users.

Exploit

Place a DLL in this directory that a privileged service is looking for. For example, WptsExtensions.dll
When Windows starts, it'll execute the code in DllMain() with SYSTEM privileges.

Impact

An unprivileged user can execute code with SYSTEM privileges.
(privilege escalation)

Severity

High

CVE ID

CVE-2020-15264

Weaknesses

No CWEs

Credits