7.2
CVSSv2

CVE-2014-5507

Published: 03/11/2014 Updated: 08/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

iBackup 10.0.0.32 and previous versions uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Trojan horse file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pro softnet corporation ibackup

Exploits

# Exploit Title: iBackup <= 100032 Local Privilege Escalation # Date: 23/01/2014 # Author: Glafkos Charalambous <glafkoscharalambous[at]unithreatcom> # Version: 100032 # Vendor: IBackup # Vendor URL: wwwibackupcom/ # CVE-2014-5507 Vulnerability Details There are weak permissions for IBackupWindows default installation w ...