Privilege Escalation in ActFax Version 7.10 from Tobit Software
CVE-2020-15843

7.3HIGH

Key Information:

Vendor

Actfax

Status
Vendor
CVE Published:
24 September 2020

What is CVE-2020-15843?

ActFax Version 7.10 Build 0335 contains a privilege escalation vulnerability caused by improper folder permissions. The affected directories grant 'Full Control' access to 'Everyone', allowing authenticated local attackers to alter critical executable files. Attackers can target the TSClientB.exe binary in the Terminal directory, which is executed upon user logon, effectively compromising the system. Additionally, they can replace binaries in the Client and Install directories, although this scenario requires further user interaction. It is essential for users and organizations utilizing ActFax to mitigate this vulnerability to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.