CVE-2017-20218
Serviio PRO 1.8 contains an unquoted search path vulnerability in the Windows service that allows local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Serviio PRO 1.8 contains an unquoted search path vulnerability in the Windows service that allows local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path. Additionally, improper directory permissions with full access for the Users group allow authenticated users to replace the executable file with arbitrary binaries, enabling privilege escalation during service startup or system reboot.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Source
- disclosure@vulncheck.com
References
- https://blogs.securiteam.com/index.php/archives/3094
- https://cxsecurity.com/issue/WLB-2017050019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125644
- https://packetstormsecurity.com/files/142384
- https://www.exploit-db.com/exploits/41959/
- https://www.vulncheck.com/advisories/serviio-pro-local-privilege-escalation-via-unquoted-path
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5405.php
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.