Privilege Escalation Vulnerability in Sage 300 ERP by Sage Group
CVE-2021-45492

7.8HIGH

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
14 July 2022

What is CVE-2021-45492?

In Sage 300 ERP (formerly known as Accpac), the installer incorrectly configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. This directory is writable by unprivileged users due to insufficient permissions set by the Sage installer, which defaults this directory to weak permissions inherited from C:. This misconfiguration can lead to DLL search-order hijacking, allowing attackers to escalate their privileges to SYSTEM level. If Global Search or Web Screens capabilities are enabled, further privilege escalation is achievable via the GlobalSearchService and Sage.CNA.WindowsService services due to similar DLL search-order vulnerabilities, as unprivileged users can modify files within the application directory. It's important to note that while older software versions install in a secure directory, official guides suggest installations in the vulnerable C:\Sage directory, making them at risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.