An issue exists in TitanFTP (aka Titan FTP) NextGen prior to 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674 (sub-issue 2). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
southrivertech titan ftp server nextgen |