The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
Metrics
Affected Vendors & Products
References
History
Fri, 29 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cradlepoint
Cradlepoint netcloud Exhange Client |
|
CPEs | cpe:2.3:a:cradlepoint:netcloud_exhange_client:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cradlepoint
Cradlepoint netcloud Exhange Client |
|
Metrics |
ssvc
|
Thu, 28 Nov 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges). | |
Title | Incorrect default permissions in Cradlepoint NetCloud Exchange | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-11-28T15:41:18.730Z
Updated: 2024-11-29T17:12:06.797Z
Reserved: 2024-11-28T10:38:45.647Z
Link: CVE-2024-11969
Vulnrichment
Updated: 2024-11-29T17:11:59.646Z
NVD
Status : Received
Published: 2024-11-28T16:15:07.190
Modified: 2024-11-28T16:15:07.190
Link: CVE-2024-11969
Redhat
No data.