Loading HuntDB...

UniFi Video v3.2.2 (Windows) Local Privileges Escalation due to weak default install directory ACLs

High
U
Ubiquiti Inc.
Submitted None

Team Summary

Official summary from Ubiquiti Inc.

The UniFi Video Windows installation `v3.7.3` and prior create directories with insecure permission, allowing unprivileged users to modify UniFi Video files and consequently escalate privileges.

Reported by mrtuxracer

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation