4.6
CVSSv2

CVE-2017-1000475

Published: 24/01/2018 Updated: 02/07/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freesshd freesshd 1.3.1

Github Repositories

Unquoted Path Service

CVE-2017-1000475: Freesshd Unquoted Service Path Prove of concept Windows 10 with freeSSHd 131, installed by default and with the option running as a system service Command to check Unquoted Service Path The service is unquoted by default The process is running as SYSTEM by default Create a Reverse Shell with MSFVenom to check the connection against an attacker and ren