CVE-2020-23834 Information
Feb 14, 2021
cve
Description
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the SYSTEMDRIVE\bd\bd.exe file. When the computer next starts the new bd.exe will be run as LocalSystem.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/boku7/BarracudaDrivev6.5-LocalPrivEsc https://www.exploit-db.com/exploits/48789
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: