The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
History

Fri, 29 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Cradlepoint
Cradlepoint netcloud Exhange Client
CPEs cpe:2.3:a:cradlepoint:netcloud_exhange_client:*:*:*:*:*:*:*:*
Vendors & Products Cradlepoint
Cradlepoint netcloud Exhange Client
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
Description The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
Title Incorrect default permissions in Cradlepoint NetCloud Exchange
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-11-28T15:41:18.730Z

Updated: 2024-11-29T17:12:06.797Z

Reserved: 2024-11-28T10:38:45.647Z

Link: CVE-2024-11969

cve-icon Vulnrichment

Updated: 2024-11-29T17:11:59.646Z

cve-icon NVD

Status : Received

Published: 2024-11-28T16:15:07.190

Modified: 2024-11-28T16:15:07.190

Link: CVE-2024-11969

cve-icon Redhat

No data.