CVE-2017-7884
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe.
- CVSS 3.0
- 8.4 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- apcupsd/apc ups daemon
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Jun/20Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99092Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038707
- http://seclists.org/fulldisclosure/2017/Jun/20Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99092Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038707
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.