CVE-2016-8742
23Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 2.0%
de la publicación al arma0 días
Publicada en NVD12 feb
1ª PoC5 dic
probabilidad de explotación
2.0%top 22% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.
Productos afectados
Apache Software Foundation · Apache CouchDBPoCs públicas encontradas — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/40865cve_referencewww.exploit-db.com/exploits/40865/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.