Description


Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

Weaknesses



CWE-427

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-427

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-11T01:15:11.550Z

3 years ago

Last modified

2025-04-07T17:15:51.873Z

11 months ago