Privilege Escalation Vulnerability in C-MOR Video Surveillance Could Lead to Root Access
CVE-2024-45173
8.8HIGH
What is CVE-2024-45173?
A vulnerability in C-MOR Video Surveillance allows the Linux user www-data, associated with the web interface, to execute certain operating system commands as root through improper privilege management of sudo. Attackers can leverage this flaw to modify critical system files, particularly the sudoers file, thereby gaining root access without a password. The ability to execute commands like cp, chown, and chmod poses a significant security risk, making it imperative for users to address this vulnerability promptly.
