[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)
SmarterMail 100.0.9693 executes its antivirus command-line configuration as NT AUTHORITY\SYSTEM, a CWE-250 flaw rated CVSS 7.2.
0day Rubbish Research Team disclosed that SmarterMail 100.0.9693 (build 9693) runs its antivirus command-line configuration with NT AUTHORITY\SYSTEM privileges, classified as CWE-250 (deployment of executable with unnecessary privileges) and rated CVSS 7.2. Control over that configuration could yield SYSTEM-level code execution on the mail server. The disclosure does not report exploitation in the wild.
- Antivirus command-line configuration executes as NT AUTHORITY\SYSTEM (CWE-250)
- Rated CVSS 7.2 in the public disclosure
- Affects SmarterMail 100.0.9693 (build 9693)
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in SmarterMail 100.0.9693 (Build 9693). Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250) CVSS: 7.2...
This source does not provide full text. Read it at seclists.org.