PT-2026-51300 · Arubasign · Arubasign
CVSS v4.0
8.8
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
ArubaSign versions prior to 4.6.6
Description
Incorrect default permissions are assigned during the installation of the software. The main executable and other program files located in "C:Program Files" have excessive permissions for the 'Everyone' group. This allows an unprivileged user to replace the main executable or its components with a malicious file to execute arbitrary code. If the malicious code runs with elevated privileges, such as Administrator or SYSTEM, it can lead to privilege escalation and full system control.
Recommendations
Update to version 4.6.6 or later.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arubasign