exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

APC UPS Daemon 3.14.14 Privilege Escalation

APC UPS Daemon 3.14.14 Privilege Escalation
Posted Jun 16, 2017
Authored by Richard Young

APC UPS Daemon versions 3.14.14 and below suffer from a privilege escalation vulnerability.

tags | exploit
advisories | CVE-2017-7884
SHA-256 | 7883eb46cb295a5d58722ffbbf84eb634440c4fa1de28144bab68e84bac41c2a

APC UPS Daemon 3.14.14 Privilege Escalation

Change Mirror Download
[+] Credits: fragsh3ll aka Richard Young
[+] Contact: https://twitter.com/fragsh3ll


Vendor
==========
http://www.apcupsd.org


Product
===========
APC UPS Daemon <= 3.14.14


Vulnerability Type
=====================
Privilege Escalation


Vendor Description
=====================
Apcupsd can be used for power mangement and controlling most of APCas UPS
models on Unix and Windows machines. Apcupsd works with most of APCas
Smart-UPS models as well as most simple signalling models such a Back-UPS,
and BackUPS-Office. During a power failure, apcupsd will inform the users
about the power failure and that a shutdown may occur. If power is not
restored, a system shutdown will follow when the battery is exhausted, a
timeout (seconds) expires, or runtime expires based on internal APC
calculations determined by power consumption rates. Apcupsd is licensed
under the GPL version 2.


CVE Reference
===============
CVE-2017-7884


Vulnerability Details
========================
The default installation of APCUPSD allows a local unprivileged user to run
arbitrary code with elevated privileges by replacing the service executable
apcupsd.exe with a malicious executable, which will run with SYSTEM
privileges at startup.


C:\apcupsd\bin\apcupsd.exe
RW BUILTIN\Administrators
RW NT AUTHORITY\SYSTEM
RW NT AUTHORITY\Authenticated Users



Exploit
==========
1) Install the application with default settings.

2) Replace the service executable located at C:\apcupsd\bin\apcupsd.exe
with an executable of your choice.

3) Restart the service or computer, the executable will run.



Disclosure Timeline:
=====================================
4/17/17 - Vendor notified
4/17/17 - Vendor acknowledged
5/6/17 - Vendor still working
6/5/17 - No response
6/14/17 - No response
6/15/17 - Public disclosure


Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close