7.8
CVSSv3

CVE-2015-8300

Published: 28/08/2017 Updated: 26/09/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Polycom BToE Connector prior to 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

polycom btoe connector

Exploits

Polycom BToE Connector up to version 230 allows unprivileged windows users to execute arbitrary code with SYSTEM privileges ...