Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
References
Configurations
No configuration.
History
23 Dec 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-23 13:15
Updated : 2024-12-23 13:15
NVD link : CVE-2024-12903
Mitre link : CVE-2024-12903
CVE.ORG link : CVE-2024-12903
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions