Privilege Escalation Vulnerability in Sage 300 ERP by Sage Group
CVE-2021-45492
What is CVE-2021-45492?
In Sage 300 ERP (formerly known as Accpac), the installer incorrectly configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. This directory is writable by unprivileged users due to insufficient permissions set by the Sage installer, which defaults this directory to weak permissions inherited from C:. This misconfiguration can lead to DLL search-order hijacking, allowing attackers to escalate their privileges to SYSTEM level. If Global Search or Web Screens capabilities are enabled, further privilege escalation is achievable via the GlobalSearchService and Sage.CNA.WindowsService services due to similar DLL search-order vulnerabilities, as unprivileged users can modify files within the application directory. It's important to note that while older software versions install in a secure directory, official guides suggest installations in the vulnerable C:\Sage directory, making them at risk.
